Vulnerability record · CVE-2026-34908 · published 22 May 2026
CVE-2026-34908: Ubiquiti UniFi OS improper access control allows unauthorized system changes
Ui · Unifi Os Server
UniFi OS devices contain an improper access control flaw (CWE-284) that lets a network-reachable actor make unauthorized changes to the system. The CVSS 3.1 base score is 10.0 (critical) with a scope-changing vector, and CISA added it to KEV with a three-day remediation due date, so it warrants immediate action. The record does not specify affected firmware versions or the exact vulnerable component.
Description
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized changes to the system.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 10.0 with scope change, unauthenticated network reach, KEV listing and very high EPSS probability make this an immediate patch-or-isolate case.
What it is
UniFi OS devices contain an improper access control flaw (CWE-284) that lets a network-reachable actor make unauthorized changes to the system. The CVSS 3.1 base score is 10.0 (critical) with a scope-changing vector, and CISA added it to KEV with a three-day remediation due date, so it warrants immediate action. The record does not specify affected firmware versions or the exact vulnerable component.
Impact
An unauthenticated attacker can modify system configuration without authorization, and the scope change means impact can extend beyond the vulnerable component to connected systems. Full confidentiality, integrity and availability impact is scored.
Attack surface
Reachable over the network with no authentication and no user interaction required (AV:N/AC:L/PR:N/UI:N). Any internet- or network-exposed UniFi OS management interface is a candidate entry point.
Exploitation
Listed in CISA KEV (added 2026-06-23, due 2026-06-26) and EPSS 30-day probability is 0.852 (99.7th percentile), indicating active exploitation is expected or observed. A third-party reference is tagged Exploit, though the record does not confirm exploit code details.
What to do
- Apply the vendor patch from Ubiquiti Security Advisory Bulletin 064 per CISA BOD 26-04 guidance.
- If patching is not immediately possible, restrict network access to UniFi OS management interfaces and discontinue use where mitigations are unavailable.
- Remove direct internet exposure of UniFi OS management ports; place management behind VPN or an allowlisted jump host.
- Audit UniFi OS devices for unauthorized configuration changes and re-validate admin credentials and API keys.
- Track the CISA KEV due date (2026-06-26) and report remediation status as required.
Detection
- Monitor UniFi OS management interface logs for configuration changes from unexpected source IPs or without a preceding authenticated session.
- Alert on inbound connections to UniFi OS management ports from the internet or untrusted network segments.
- Baseline device configuration and alert on unexpected changes to admin accounts, network settings or firewall rules.
- Hunt for the exploitation activity described in the third-party advisory reference and correlate with UniFi OS device telemetry.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2026-34908 to the Known Exploited Vulnerabilities catalog on 23 June 2026 as "Ubiquiti UniFi OS Improper Access Control Vulnerability". Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 26 June 2026.
Affected products
31 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://community.ui.com/releases/Security-Advisory-Bulletin-064-064/84811c09-4cf4-42ab-bd61-cc994445963b | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-34908 | US Government Resource |
| https://www.pwndefend.com/2026/06/09/cve-2026-34910-exploitation-itw-building-a-botnet-mirai/ | ExploitThird Party Advisory |
Track CVE-2026-34908 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-34908), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.