Vulnerability record · CVE-2026-34909 · published 22 May 2026
CVE-2026-34909: UniFi OS path traversal allows unauthenticated file access
Ui · Unifi Os Server
UniFi OS devices contain a path traversal flaw (CWE-22) that lets a network-reachable attacker read files on the underlying system. Because the exposed files can be manipulated to reach an underlying account, the flaw can lead to full compromise of the device. The vendor has published a security advisory bulletin with patch information.
Description
A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to access an underlying account.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 10.0, unauthenticated network reachability, CISA KEV listing, and very high EPSS make this an urgent patch-first issue.
What it is
UniFi OS devices contain a path traversal flaw (CWE-22) that lets a network-reachable attacker read files on the underlying system. Because the exposed files can be manipulated to reach an underlying account, the flaw can lead to full compromise of the device. The vendor has published a security advisory bulletin with patch information.
Impact
An attacker gains read access to arbitrary files on the underlying system and, by manipulating those files, can obtain access to an underlying account. The CVSS scope change (S:C) and high confidentiality, integrity and availability impact indicate potential full device compromise.
Attack surface
Reachable over the network (AV:N) with no authentication (PR:N) and no user interaction (UI:N), so any host that can reach the affected UniFi OS interface can attempt the traversal. No credentials or victim action are required.
Exploitation
The vulnerability is listed in CISA KEV (added 2026-06-23, due 2026-06-26) and EPSS is 0.65044 (99.21st percentile), indicating active exploitation is expected or observed. A third-party reference tagged Exploit describes in-the-wild exploitation building a Mirai botnet, though that reference names a different CVE id.
What to do
- Apply the vendor patch from the Ubiquiti Security Advisory Bulletin 064 as the first action.
- If patching is not immediately possible, restrict network access to UniFi OS management interfaces and remove direct internet exposure.
- Follow CISA BOD 26-04 guidance for prioritizing this update and for cloud services, or discontinue use of the product if mitigations are unavailable.
- Rotate credentials for any accounts reachable through the underlying system after patching.
- Verify all listed UniFi OS, Dream Machine, Cloud Gateway, and UNVR firmware products are updated, not just the primary controller.
Detection
- Monitor web and application logs on UniFi OS devices for path traversal patterns such as ../ sequences or encoded variants in request paths.
- Alert on unexpected outbound connections from UniFi OS devices, which may indicate botnet enrollment or post-exploitation activity.
- Audit file access and account activity on the underlying system for reads of sensitive files or creation of new accounts.
- Check for unauthorized configuration changes or new administrative users on affected devices.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2026-34909 to the Known Exploited Vulnerabilities catalog on 23 June 2026 as "Ubiquiti UniFi OS Path Traversal Vulnerability". Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 26 June 2026.
Affected products
32 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://community.ui.com/releases/Security-Advisory-Bulletin-064-064/84811c09-4cf4-42ab-bd61-cc994445963b | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-34909 | US Government Resource |
| https://www.pwndefend.com/2026/06/09/cve-2026-34910-exploitation-itw-building-a-botnet-mirai/ | ExploitThird Party Advisory |
Track CVE-2026-34909 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-34909), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.