Fixing and finding
Jump to remediation plan
CVE ID

CVE-2026-34909

Published 2026-05-22
Updated 2 months ago
Vendor/s
Ubiquiti
Product/s
UniFi OS
Version/s
* > 5.0.8
KEV Status
Active Exploitation
Listed in CISA's Known Exploited Vulnerabilities catalog. Active exploitation observed in the wild.
CVSS Score (v3.1)
10
/ 10
Critical
Severity Details
Base score
10 Critical
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High

Description

CVE-2026-34909 is a critical CVSS 10 path traversal vulnerability in Ubiquiti UniFi OS allowing account takeover. Update firmware immediately.

CPE

Ubiquiti logo
Ubiquiti
Product Version Start Version End (excl.) Status
unifi_os_server * 5.0.8 vulnerable
unifi_cloud_gateway_industrial_firmware * 5.1.12 vulnerable
unifi_cloud_gateway_industrial - - unaffected
unifi_dream_machine_firmware * 5.1.12 vulnerable
unifi_dream_machine - - unaffected
unifi_dream_machine_pro_firmware * 5.1.12 vulnerable
unifi_dream_machine_pro - - unaffected
unifi_dream_machine_special_edition_firmware * 5.1.12 vulnerable
unifi_dream_machine_special_edition - - unaffected
unifi_dream_machine_pro_max_firmware * 5.1.12 vulnerable
unifi_dream_machine_pro_max - - unaffected
enterprise_fortress_gateway_firmware * 5.1.12 vulnerable
enterprise_fortress_gateway - - unaffected
unifi_dream_wall_firmware * 5.1.12 vulnerable
unifi_dream_wall - - unaffected
unifi_dream_router_firmware * 5.1.12 vulnerable
unifi_dream_router - - unaffected
unifi_dream_router_7_firmware * 5.1.12 vulnerable
unifi_dream_router_7 - - unaffected
unifi_express_7_firmware * 5.1.12 vulnerable
unifi_express_7 - - unaffected
unifi_network_video_recorder_firmware * 5.1.12 vulnerable
unifi_network_video_recorder - - unaffected
unifi_network_video_recorder_pro_firmware * 5.1.12 vulnerable
unifi_network_video_recorder_pro - - unaffected
unifi_network_video_recorder_instant_firmware * 5.1.12 vulnerable
unifi_network_video_recorder_instant - - unaffected
enterprise_network_video_recorder_firmware * 5.1.12 vulnerable
enterprise_network_video_recorder - - unaffected
unifi_cloud_gateway_ultra_firmware * 5.1.12 vulnerable
unifi_cloud_gateway_ultra - - unaffected
unifi_cloud_gateway_max_firmware * 5.1.12 vulnerable
unifi_cloud_gateway_max - - unaffected
unifi_cloud_gateway_fiber_firmware * 5.1.12 vulnerable
unifi_cloud_gateway_fiber - - unaffected
unifi_dream_router_5g_max_firmware * 5.1.12 vulnerable
unifi_dream_router_5g_max - - unaffected
enterprise_network_video_recorder_core_firmware * 5.1.12 vulnerable
enterprise_network_video_recorder_core - - unaffected
unifi_cloud_key_plus_firmware * 5.1.12 vulnerable
unifi_cloud_key_plus - - unaffected
unifi_cloudkey_firmware * 5.1.12 vulnerable
unifi_cloudkey - - unaffected
unifi_cloudkey_enterprise_firmware * 5.1.12 vulnerable
unifi_cloudkey_enterprise - - unaffected
unifi_network_video_recorder_g2_firmware * 5.1.12 vulnerable
unifi_network_video_recorder_g2 - - unaffected
unifi_network_video_recorder_g2_pro_firmware * 5.1.12 vulnerable
unifi_network_video_recorder_g2_pro - - unaffected
unifi_dream_machine_beast_firmware * 5.1.11 vulnerable
unifi_dream_machine_beast - - unaffected
unas_2_firmware * 5.1.10 vulnerable
unas_2 - - unaffected
unas_4_firmware * 5.1.10 vulnerable
unas_4 - - unaffected
unas_pro_firmware * 5.1.10 vulnerable
unas_pro - - unaffected
unas_pro_4_firmware * 5.1.10 vulnerable
unas_pro_4 - - unaffected
unas_pro_8_firmware * 5.1.10 vulnerable
unas_pro_8 - - unaffected
unifi_express_firmware * 4.0.14 vulnerable
unifi_express - - unaffected

Related weakness (CWE)

CWE-22

Remediation plan

1

Apply official patches

Download and install the latest firmware updates from the Ubiquiti UI community or official download portal. Ubiquiti has released security bulletins addressing this path traversal flaw across various hardware platforms.

2

Update affected systems

Ensure UniFi OS Server is updated to version 5.0.8 or later. Most gateways and NVRs, including UDM, UDR, and UNVR, must be updated to firmware version 5.1.12 or higher. UniFi Express requires version 4.0.14.

3

Restrict access

Minimize the exposure of UniFi OS management interfaces to the public internet. Use VPNs or trusted management subnets to access device consoles and implement strict firewall rules to block unauthorized network traffic.

4

Monitor for exploitation

Review system logs for unusual file access patterns or directory traversal attempts (e.g., "../" sequences in web requests). Audit administrative account activity for unauthorized changes or new, unrecognized user accounts.

Detection Guidance

Detect exploitation by monitoring web server logs for URI patterns containing directory traversal sequences like "../" or "%2e%2e/". Look for unauthorized access to sensitive system files such as /etc/passwd or configuration databases. Network-based IDS/IPS signatures should target UniFi management ports (typically 443 or 8443) for anomalous path requests. Additionally, monitor for unexpected administrative account creations or modifications within the UniFi OS environment that may indicate a successful account takeover.

References

Sources

NIST National Vulnerability Database (NVD)
CISA Known Exploited Vulnerabilities (KEV)

Experience superior visibility and a simpler approach to cyber risk management