Fixing and finding

[Jump to remediation plan](#remediation)

CVE ID

# CVE-2026-34909

Published 2026-05-22

Updated 2 months ago

Vendor/s

Ubiquiti

Product/s

UniFi OS

Version/s

\* > 5.0.8

KEV Status

Active Exploitation

Listed in CISA's Known Exploited Vulnerabilities catalog. Active exploitation observed in the wild.

CVSS Score (v3.1)

10

/ 10

Critical

Severity Details

Base score

10 Critical

Attack vector

Network

Attack complexity

Low

Privileges required

None

User interaction

None

Scope

Changed

Confidentiality

High

Integrity

High

Availability

High

Table of Contents

[Description ](#description)[Why this matters ](#why-this-matters)[CPE ](#cpe)[Related weakness (CWE) ](#cwe)[Remediation plan ](#remediation)[Detection Guidance ](#detection-guidance)[References ](#references)[Sources](#sources)

[Description ](#description)[Why this matters ](#why-this-matters)[CPE ](#cpe)[Related weakness (CWE) ](#cwe)[Remediation plan ](#remediation)[Detection Guidance ](#detection-guidance)[References ](#references)[Sources](#sources)

## Description

CVE-2026-34909 is a critical CVSS 10 path traversal vulnerability in Ubiquiti UniFi OS allowing account takeover. Update firmware immediately.

## Why this matters

CVE-2026-34909 is a critical path traversal vulnerability in Ubiquiti UniFi OS with a maximum CVSS score of 10.0. Its inclusion in the CISA Known Exploited Vulnerabilities (KEV) catalog indicates active exploitation in the wild. A network-based attacker can exploit this flaw to access and manipulate sensitive system files, potentially leading to full account takeover and persistent access to the underlying UniFi device. Given the central role these devices play in network management and security, a compromise could grant attackers significant control over the entire network infrastructure, making immediate remediation essential for all affected organizations.

## CPE

Ubiquiti

| Product                                              | Version Start | Version End (excl.) | Status     |
| ---------------------------------------------------- | ------------- | ------------------- | ---------- |
| unifi\_os\_server                                    | \*            | 5.0.8               | vulnerable |
| unifi\_cloud\_gateway\_industrial\_firmware          | \*            | 5.1.12              | vulnerable |
| unifi\_cloud\_gateway\_industrial                    | -             | -                   | unaffected |
| unifi\_dream\_machine\_firmware                      | \*            | 5.1.12              | vulnerable |
| unifi\_dream\_machine                                | -             | -                   | unaffected |
| unifi\_dream\_machine\_pro\_firmware                 | \*            | 5.1.12              | vulnerable |
| unifi\_dream\_machine\_pro                           | -             | -                   | unaffected |
| unifi\_dream\_machine\_special\_edition\_firmware    | \*            | 5.1.12              | vulnerable |
| unifi\_dream\_machine\_special\_edition              | -             | -                   | unaffected |
| unifi\_dream\_machine\_pro\_max\_firmware            | \*            | 5.1.12              | vulnerable |
| unifi\_dream\_machine\_pro\_max                      | -             | -                   | unaffected |
| enterprise\_fortress\_gateway\_firmware              | \*            | 5.1.12              | vulnerable |
| enterprise\_fortress\_gateway                        | -             | -                   | unaffected |
| unifi\_dream\_wall\_firmware                         | \*            | 5.1.12              | vulnerable |
| unifi\_dream\_wall                                   | -             | -                   | unaffected |
| unifi\_dream\_router\_firmware                       | \*            | 5.1.12              | vulnerable |
| unifi\_dream\_router                                 | -             | -                   | unaffected |
| unifi\_dream\_router\_7\_firmware                    | \*            | 5.1.12              | vulnerable |
| unifi\_dream\_router\_7                              | -             | -                   | unaffected |
| unifi\_express\_7\_firmware                          | \*            | 5.1.12              | vulnerable |
| unifi\_express\_7                                    | -             | -                   | unaffected |
| unifi\_network\_video\_recorder\_firmware            | \*            | 5.1.12              | vulnerable |
| unifi\_network\_video\_recorder                      | -             | -                   | unaffected |
| unifi\_network\_video\_recorder\_pro\_firmware       | \*            | 5.1.12              | vulnerable |
| unifi\_network\_video\_recorder\_pro                 | -             | -                   | unaffected |
| unifi\_network\_video\_recorder\_instant\_firmware   | \*            | 5.1.12              | vulnerable |
| unifi\_network\_video\_recorder\_instant             | -             | -                   | unaffected |
| enterprise\_network\_video\_recorder\_firmware       | \*            | 5.1.12              | vulnerable |
| enterprise\_network\_video\_recorder                 | -             | -                   | unaffected |
| unifi\_cloud\_gateway\_ultra\_firmware               | \*            | 5.1.12              | vulnerable |
| unifi\_cloud\_gateway\_ultra                         | -             | -                   | unaffected |
| unifi\_cloud\_gateway\_max\_firmware                 | \*            | 5.1.12              | vulnerable |
| unifi\_cloud\_gateway\_max                           | -             | -                   | unaffected |
| unifi\_cloud\_gateway\_fiber\_firmware               | \*            | 5.1.12              | vulnerable |
| unifi\_cloud\_gateway\_fiber                         | -             | -                   | unaffected |
| unifi\_dream\_router\_5g\_max\_firmware              | \*            | 5.1.12              | vulnerable |
| unifi\_dream\_router\_5g\_max                        | -             | -                   | unaffected |
| enterprise\_network\_video\_recorder\_core\_firmware | \*            | 5.1.12              | vulnerable |
| enterprise\_network\_video\_recorder\_core           | -             | -                   | unaffected |
| unifi\_cloud\_key\_plus\_firmware                    | \*            | 5.1.12              | vulnerable |
| unifi\_cloud\_key\_plus                              | -             | -                   | unaffected |
| unifi\_cloudkey\_firmware                            | \*            | 5.1.12              | vulnerable |
| unifi\_cloudkey                                      | -             | -                   | unaffected |
| unifi\_cloudkey\_enterprise\_firmware                | \*            | 5.1.12              | vulnerable |
| unifi\_cloudkey\_enterprise                          | -             | -                   | unaffected |
| unifi\_network\_video\_recorder\_g2\_firmware        | \*            | 5.1.12              | vulnerable |
| unifi\_network\_video\_recorder\_g2                  | -             | -                   | unaffected |
| unifi\_network\_video\_recorder\_g2\_pro\_firmware   | \*            | 5.1.12              | vulnerable |
| unifi\_network\_video\_recorder\_g2\_pro             | -             | -                   | unaffected |
| unifi\_dream\_machine\_beast\_firmware               | \*            | 5.1.11              | vulnerable |
| unifi\_dream\_machine\_beast                         | -             | -                   | unaffected |
| unas\_2\_firmware                                    | \*            | 5.1.10              | vulnerable |
| unas\_2                                              | -             | -                   | unaffected |
| unas\_4\_firmware                                    | \*            | 5.1.10              | vulnerable |
| unas\_4                                              | -             | -                   | unaffected |
| unas\_pro\_firmware                                  | \*            | 5.1.10              | vulnerable |
| unas\_pro                                            | -             | -                   | unaffected |
| unas\_pro\_4\_firmware                               | \*            | 5.1.10              | vulnerable |
| unas\_pro\_4                                         | -             | -                   | unaffected |
| unas\_pro\_8\_firmware                               | \*            | 5.1.10              | vulnerable |
| unas\_pro\_8                                         | -             | -                   | unaffected |
| unifi\_express\_firmware                             | \*            | 4.0.14              | vulnerable |
| unifi\_express                                       | -             | -                   | unaffected |

## Related weakness (CWE)

CWE-22

## Remediation plan

1

### Apply official patches

Download and install the latest firmware updates from the Ubiquiti UI community or official download portal. Ubiquiti has released security bulletins addressing this path traversal flaw across various hardware platforms.

2

### Update affected systems

Ensure UniFi OS Server is updated to version 5.0.8 or later. Most gateways and NVRs, including UDM, UDR, and UNVR, must be updated to firmware version 5.1.12 or higher. UniFi Express requires version 4.0.14.

3

### Restrict access

Minimize the exposure of UniFi OS management interfaces to the public internet. Use VPNs or trusted management subnets to access device consoles and implement strict firewall rules to block unauthorized network traffic.

4

### Monitor for exploitation

Review system logs for unusual file access patterns or directory traversal attempts (e.g., "../" sequences in web requests). Audit administrative account activity for unauthorized changes or new, unrecognized user accounts.

## Detection Guidance

Detect exploitation by monitoring web server logs for URI patterns containing directory traversal sequences like "../" or "%2e%2e/". Look for unauthorized access to sensitive system files such as /etc/passwd or configuration databases. Network-based IDS/IPS signatures should target UniFi management ports (typically 443 or 8443) for anomalous path requests. Additionally, monitor for unexpected administrative account creations or modifications within the UniFi OS environment that may indicate a successful account takeover.

## References

[https://community.ui.com/releases/Security-Advisory-Bulletin-064-064/84811c09-4cf4-42ab-bd61-cc994445963b Patch Vendor Advisory ](https://community.ui.com/releases/Security-Advisory-Bulletin-064-064/84811c09-4cf4-42ab-bd61-cc994445963b)[https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field\_cve=CVE-2026-34909 US Government Resource ](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-34909)[https://www.pwndefend.com/2026/06/09/cve-2026-34910-exploitation-itw-building-a-botnet-mirai/ Exploit Third Party Advisory](https://www.pwndefend.com/2026/06/09/cve-2026-34910-exploitation-itw-building-a-botnet-mirai/)

## Sources

NIST National Vulnerability Database (NVD)

CISA Known Exploited Vulnerabilities (KEV)

Experience superior visibility and a simpler approach to cyber risk management

[Get a demo](https://www.upguard.com/contact-sales)

[Free trial](https://www.upguard.com/demo)
