CVE-2026-34908

unifi_os_server: Improper Access Control (CVE-2026-34908)

Situation assessment

An attacker with network access can exploit an improper access control vulnerability in Ubiquiti UniFi OS to make unauthorized changes to the system. This affects multiple UniFi OS products and firmware versions, including UniFi OS Server 5.0.8 and various UniFi Dream Machine firmware versions 5.1.12. The vulnerability is actively being exploited in the wild, posing a high risk to affected systems. It is imperative to update the affected devices to the latest firmware version to mitigate the risk.

Affected

  • ui/unifi_os_server lt *..5.0.8
  • ui/unifi_cloud_gateway_industrial_firmware lt *..5.1.12
  • ui/unifi_dream_machine_firmware lt *..5.1.12
  • ui/unifi_dream_machine_pro_firmware lt *..5.1.12
  • ui/unifi_dream_machine_special_edition_firmware lt *..5.1.12
  • ui/unifi_dream_machine_pro_max_firmware lt *..5.1.12
  • ui/enterprise_fortress_gateway_firmware lt *..5.1.12
  • ui/unifi_dream_wall_firmware lt *..5.1.12
  • ui/unifi_dream_router_firmware lt *..5.1.12
  • ui/unifi_dream_router_7_firmware lt *..5.1.12
  • ui/unifi_express_7_firmware lt *..5.1.12
  • ui/unifi_network_video_recorder_firmware lt *..5.1.12
  • ui/unifi_network_video_recorder_pro_firmware lt *..5.1.12
  • ui/unifi_network_video_recorder_instant_firmware lt *..5.1.12
  • ui/enterprise_network_video_recorder_firmware lt *..5.1.12
  • ui/unifi_cloud_gateway_ultra_firmware lt *..5.1.12
  • ui/unifi_cloud_gateway_max_firmware lt *..5.1.12
  • ui/unifi_cloud_gateway_fiber_firmware lt *..5.1.12
  • ui/unifi_dream_router_5g_max_firmware lt *..5.1.12
  • ui/enterprise_network_video_recorder_core_firmware lt *..5.1.12
  • ui/unifi_cloud_key_plus_firmware lt *..5.1.12
  • ui/unifi_cloudkey_firmware lt *..5.1.12
  • ui/unifi_cloudkey_enterprise_firmware lt *..5.1.12
  • ui/unifi_network_video_recorder_g2_firmware lt *..5.1.12
  • ui/unifi_network_video_recorder_g2_pro_firmware lt *..5.1.12
  • ui/unifi_dream_machine_beast_firmware lt *..5.1.11
  • ui/unas_2_firmware lt *..5.1.10
  • ui/unas_4_firmware lt *..5.1.10
  • ui/unas_pro_firmware lt *..5.1.10
  • ui/unas_pro_4_firmware lt *..5.1.10
  • ui/unas_pro_8_firmware lt *..5.1.10

Response & Mitigation

Why act now?

Prioritisation rationale

CVE-2026-34908 carries a CVSS v3 score of 10.0 (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) and sits at the 99.7th EPSS percentile, meaning virtually no comparable vulnerability has a higher exploitation probability. The unauthenticated, network-accessible attack path with a full scope change makes this a critical risk for any organisation using UniFi OS devices as network gateways or firewall platforms — a deployment pattern common in NIS2-regulated sectors such as energy, healthcare, and industrial control environments. Successful exploitation allows an attacker to alter network configuration without any prior credentials, potentially dismantling segmentation controls, VPN policies, and access rules across the entire network. Although CISA has not flagged known ransomware campaign use at this time, the ability to establish persistence and enable lateral movement represents a severe secondary risk; organisations with internet-exposed management interfaces must treat this as a P1 incident and patch or isolate immediately.

Runbook · Step 1

Immediate response (0-24 h)

  • Apply vendor patch immediately: Ubiquiti has released firmware updates for all affected platforms. Target versions are above UniFi OS Server 5.0.8 and device firmware 5.1.12 — verify exact version numbers in the Ubiquiti Security Advisory and deploy via the UniFi Network Application update menu or the UI console without delay.
  • Isolate management interfaces at the network layer: Move all affected UniFi OS devices (Dream Machine family, Dream Wall, Cloud Gateway Industrial, Enterprise Fortress Gateway) into a dedicated management VLAN, or tighten existing ACLs so that only authorised administrator workstations can reach TCP 443 (UI console) and TCP 22 (SSH).
  • Disable cloud remote access if not operationally required: Temporarily turn off remote access via unifi.ui.com under UniFi OS → System → Remote Access to eliminate the internet-facing attack surface until the patch is confirmed deployed.
  • Invalidate all active sessions and rotate credentials: After patching, terminate all active admin sessions, rotate API keys and tokens, and reset passwords for every local and cloud account that had access to affected devices.
  • Inventory all affected instances: Enumerate every UniFi OS device running firmware ≤ 5.1.12 or OS Server ≤ 5.0.8 (network scan on TCP 443 with service fingerprinting, or via ubnt-tools) and prioritise patching by exposure level — internet-facing first.

Runbook · Step 2

Mitigation layers

  • L2/L3 network segmentation: Restrict management interfaces to a dedicated out-of-band management VLAN; enforce a full deny rule between production VLANs and the management VLAN at the firewall level.
  • Firewall ACLs on management ports: Limit inbound traffic on TCP 443, TCP 8443, TCP 22, and UDP 3478 (STUN) to an explicit allowlist of administrator source IPs; block all other sources with an explicit deny entry.
  • IPS/IDS rule activation: On upstream IPS platforms (Suricata, Snort), enable rules alerting on unexpected POST/PUT/DELETE requests to /api/ and /proxy/network/api/ originating from non-administrative source IPs; set a low threshold for HTTP 4xx responses on these endpoints.
  • Least-privilege IAM for UniFi accounts: Reduce the number of administrator-role accounts to the operational minimum; enforce read-only roles for monitoring accounts; enable multi-factor authentication (TOTP) for all admin accounts.
  • Cloud console IP allowlisting: If cloud access cannot be disabled, configure IP allowlisting in the Ubiquiti account settings and enable geo-blocking for regions where no administrative access is expected.

Runbook · Step 3

Detection rules

  • Web server access log (nginx/UniFi OS): Anomalous PUT/PATCH/DELETE requests to /api/ or /proxy/network/api/ from source IPs outside the management subnet — SPL snippet: index=proxy_logs uri_path="/api/*" (method=PUT OR method=PATCH OR method=DELETE) NOT src_ip IN (management_subnet) | stats count by src_ip, uri_path
  • Network telemetry (Zeek/Suricata): TCP 443 or TCP 8443 connections to UniFi OS devices originating from hosts outside the management VLAN; alert on sessions lasting > 60 s with > 50 kB data transfer where no prior authentication handshake is observed.
  • Syslog / UniFi OS audit log: Configuration change events (cfg_change or admin_action) performed by accounts created within the last 24 hours or accounts with no prior login history — Sigma shape: title: UniFi OS Unauthorized Config Change | logsource: product: unifi_os | detection: keywords: ['cfg_change', 'admin_action'] filter: account_age < 24h
  • EDR/endpoint (if UniFi OS host is accessible): Unexpected child processes spawned by unifi-os or mcad; specifically shell execution (/bin/sh, /bin/bash) as a child of the UniFi service process — Sysmon EID 1 or auditd EXECVE with the UniFi process as parent PID.
  • Authentication log: Multiple successful logins from different source IPs within a short window (< 5 min) for the same admin account — indicative of session hijacking or token reuse.

Description

A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized changes to the system.

Affected operating systems

  • other

    ui / enterprise_fortress_gateway_firmware

  • other

    ui / enterprise_network_video_recorder_core_firmware

  • other

    ui / enterprise_network_video_recorder_firmware

  • other

    ui / unas_2_firmware

  • other

    ui / unas_4_firmware

  • other

    ui / unas_pro_4_firmware

  • other

    ui / unas_pro_8_firmware

  • other

    ui / unas_pro_firmware

  • other

    ui / unifi_cloud_gateway_fiber_firmware

  • other

    ui / unifi_cloud_gateway_industrial_firmware

  • other

    ui / unifi_cloud_gateway_max_firmware

  • other

    ui / unifi_cloud_gateway_ultra_firmware

  • other

    ui / unifi_cloud_key_plus_firmware

  • other

    ui / unifi_cloudkey_enterprise_firmware

  • other

    ui / unifi_cloudkey_firmware

  • other

    ui / unifi_dream_machine_beast_firmware

  • other

    ui / unifi_dream_machine_firmware

  • other

    ui / unifi_dream_machine_pro_firmware

  • other

    ui / unifi_dream_machine_pro_max_firmware

  • other

    ui / unifi_dream_machine_special_edition_firmware

  • other

    ui / unifi_dream_router_5g_max_firmware

  • other

    ui / unifi_dream_router_7_firmware

  • other

    ui / unifi_dream_router_firmware

  • other

    ui / unifi_dream_wall_firmware

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

uiunifi_os_server
5.0.8fixed from 5.0.8

Metrics

10.0
Source: nvd-v3
96.7 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
Actively exploited
Show all metrics
Severity
critical
actively exploited (KEV)
15.2 %
Elevated — model estimates 10-50% exploitation likelihood.
Published
2026-06-23 00:00 UTC
CWE-284

Weakness classes (CWE)

  • CWE-284Pillar

    Improper Access Control

    The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

    cwe.mitre.org →

Public exploit references

Public proof-of-concepts and detection templates for this vulnerability. Maturity ranges from reported PoCs through working detection scripts up to fully weaponized exploit modules. NEOSEC mirrors the code internally for forensic analysis; externally we only link to the original sources.

References & sources

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Translated2026-07-23 16:10 UTC· nvd@nist.gov
    • Translation: Title: varios productos de Ubiquiti, Description: Un actor malicioso con acceso a la red podría explotar una vulnerabilidad de control de acceso inadecuado encontrada en dispositivos UniFi OS para realizar cambios no autorizados en el sistema.
  2. Initial Analysis2026-06-24 14:50 UTC· nvd@nist.gov
    • CPE Configuration: OR *cpe:2.3:a:ui:unifi_os_server:*:*:*:*:*:*:*:* versions up to (excluding) 5.0.8
    • CPE Configuration: AND OR *cpe:2.3:o:ui:unifi_cloud_gateway_industrial_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 5.1.12 OR cpe:2.3:h:ui:unifi_cloud_gateway_industrial:-:*:*:*:*:*:*:*
    • CPE Configuration: AND OR *cpe:2.3:o:ui:unifi_dream_machine_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 5.1.12 OR cpe:2.3:h:ui:unifi_dream_machine:-:*:*:*:*:*:*:*
    • CPE Configuration: AND OR *cpe:2.3:o:ui:unifi_dream_machine_pro_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 5.1.12 OR cpe:2.3:h:ui:unifi_dream_machine_pro:-:*:*:*:*:*:*:*
  3. CVE Modified2026-06-24 05:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-34908","role":"CISA Coordinator","options":[{"exploitation":"active"},{"automatable":"yes"},{"technic… → {"id":"CVE-2026-34908","role":"CISA Coordinator","options":[{"exploitation":"active"},{"automatable":"yes"},{"technic…
  4. CVE CISA KEV Update2026-06-23 19:00 UTC· 9119a7d8-5eab-497f-8521-727c672e3725
    • Date Added: 2026-06-23
    • Due Date: 2026-06-23
    • Required Action: 2026-06-23
    • Vulnerability Name: 2026-06-23
  5. CVE Modified2026-06-23 18:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • Reference: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-34908
    • Reference: https://www.pwndefend.com/2026/06/09/cve-2026-34910-exploitation-itw-building-a-botnet-mirai/
    • SSVC: {"id":"CVE-2026-34908","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"yes"},{"technical… → {"id":"CVE-2026-34908","role":"CISA Coordinator","options":[{"exploitation":"active"},{"automatable":"yes"},{"technic…

Linked advisories