← Vulnerability feed

Vulnerability record · CVE-2026-34911 · published 22 May 2026

CVE-2026-34911: Ui unifi os server path traversal vulnerability

Ui · Unifi Os Server

A malicious actor with access to the network and low privileges could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to obtain sensitive information.

7.7 CVSS 3.1 High EPSS 0.59% · top 53.9% CWE-22 · Path traversal
7.7CVSS 3.1 base score
0.59%EPSS exploitation probability, 30 days
NoNot in CISA KEV
31Affected product versions listed by NVD
1References
23 Jul 2026Last modified by NVD

Description

A malicious actor with access to the network and low privileges could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to obtain sensitive information.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

Affected products

31 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-34911 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2026-34908Ubiquiti UniFi OS improper access control allows unauthorized system changesUniFi OS devices contain an improper access control flaw (CWE-284) that lets a network-reachable actor make unauthorized changes to the system. The C…KEVEPSS 15%analysed10.0CVE-2026-34909UniFi OS path traversal allows unauthenticated file accessUniFi OS devices contain a path traversal flaw (CWE-22) that lets a network-reachable attacker read files on the underlying system. Because the expos…KEVEPSS 1.8%analysed10.0CVE-2026-34910Ubiquiti UniFi OS input validation flaw allows command injectionUniFi OS devices contain an improper input validation vulnerability (CWE-20) that lets a network-reachable attacker inject and execute commands. It a…KEVEPSS 46%analysed8.8CVE-2026-55112Ui unifi dream machine pro firmware improper access control vulnerabilityA malicious actor with access to the network and low privileges and under certain conditions could exploit an Improper Access Control vulnerability f…EPSS 0.36%8.8CVE-2026-54404Ui unifi dream machine beast firmware sql injection vulnerabilityA malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found in UniFi …EPSS 0.49%8.8CVE-2026-54401Ui unifi os server server-side request forgery (ssrf) vulnerabilityA malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) to escalate privileges within such…EPSS 0.43%8.8CVE-2026-54402Ui unifi os server improper input validation vulnerabilityA malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi OS to execute…EPSS 1.8%8.6CVE-2026-54403Ui unifi os server path traversal vulnerabilityA malicious actor with access to the network could exploit a Path Traversal vulnerability found in certain devices running UniFi OS to bypass authent…EPSS 0.77%

Source: NIST National Vulnerability Database (record CVE-2026-34911), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.