Vulnerability record · CVE-2026-34910 · published 22 May 2026
CVE-2026-34910: Ubiquiti UniFi OS input validation flaw allows command injection
Ui · Unifi Os Server
UniFi OS devices contain an improper input validation vulnerability (CWE-20) that lets a network-reachable attacker inject and execute commands. It affects a broad set of UniFi OS server, gateway, Dream Machine and network video recorder firmware products. Given the unauthenticated network vector and critical severity, it is a high-value target for edge-device compromise.
Description
A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network command injection with a CVSS score of 10, active KEV listing, in-the-wild exploitation, and near-top EPSS probability make this an urgent patch-first issue.
What it is
UniFi OS devices contain an improper input validation vulnerability (CWE-20) that lets a network-reachable attacker inject and execute commands. It affects a broad set of UniFi OS server, gateway, Dream Machine and network video recorder firmware products. Given the unauthenticated network vector and critical severity, it is a high-value target for edge-device compromise.
Impact
An attacker can execute arbitrary commands on the affected device, gaining control of the appliance and potentially pivoting into the network it protects. Because the device is a gateway or controller, compromise can expose management functions and connected infrastructure.
Attack surface
Reachable over the network with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. Any internet- or network-exposed UniFi OS management interface is a candidate entry point.
Exploitation
Listed in CISA KEV with a 2026-06-23 addition and a 2026-06-26 remediation due date, and a third-party reference tagged Exploit describes in-the-wild exploitation building a Mirai botnet. EPSS is 0.87468 (99.7th percentile), indicating very high predicted exploitation likelihood.
What to do
- Apply the vendor patch from Ubiquiti Security Advisory Bulletin 064 per CISA BOD 26-04 guidance.
- If patching is not immediately possible, restrict network access to UniFi OS management interfaces and remove internet exposure.
- Segment UniFi OS devices from production networks and limit management access to trusted administrative hosts.
- Monitor for and follow CISA Forensics Triage Requirements for potentially compromised appliances.
- Discontinue use of the product if mitigations are unavailable, as directed by the KEV required action.
Detection
- Hunt for unexpected outbound connections or botnet command-and-control traffic from UniFi OS devices.
- Review device and management logs for anomalous command execution, new processes, or configuration changes.
- Alert on exploitation attempts against UniFi OS management endpoints from untrusted network sources.
- Baseline normal device behavior and flag deviations such as new listening services or credential changes.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2026-34910 to the Known Exploited Vulnerabilities catalog on 23 June 2026 as "Ubiquiti UniFi OS Improper Input Validation Vulnerability". Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 26 June 2026.
Affected products
31 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://community.ui.com/releases/Security-Advisory-Bulletin-064-064/84811c09-4cf4-42ab-bd61-cc994445963b | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-34910 | US Government Resource |
| https://www.pwndefend.com/2026/06/09/cve-2026-34910-exploitation-itw-building-a-botnet-mirai/ | ExploitThird Party Advisory |
Track CVE-2026-34910 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-34910), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.