CVE-2026-34908
unifi_os_server: Improper Access Control (CVE-2026-34908)
Situation assessment
An attacker with network access can exploit an improper access control vulnerability in Ubiquiti UniFi OS to make unauthorized changes to the system. This affects multiple UniFi OS products and firmware versions, including UniFi OS Server 5.0.8 and various UniFi Dream Machine firmware versions 5.1.12. The vulnerability is actively being exploited in the wild, posing a high risk to affected systems. It is imperative to update the affected devices to the latest firmware version to mitigate the risk.
Affected
- ui/unifi_os_server
lt *..5.0.8 - ui/unifi_cloud_gateway_industrial_firmware
lt *..5.1.12 - ui/unifi_dream_machine_firmware
lt *..5.1.12 - ui/unifi_dream_machine_pro_firmware
lt *..5.1.12 - ui/unifi_dream_machine_special_edition_firmware
lt *..5.1.12 - ui/unifi_dream_machine_pro_max_firmware
lt *..5.1.12 - ui/enterprise_fortress_gateway_firmware
lt *..5.1.12 - ui/unifi_dream_wall_firmware
lt *..5.1.12 - ui/unifi_dream_router_firmware
lt *..5.1.12 - ui/unifi_dream_router_7_firmware
lt *..5.1.12 - ui/unifi_express_7_firmware
lt *..5.1.12 - ui/unifi_network_video_recorder_firmware
lt *..5.1.12 - ui/unifi_network_video_recorder_pro_firmware
lt *..5.1.12 - ui/unifi_network_video_recorder_instant_firmware
lt *..5.1.12 - ui/enterprise_network_video_recorder_firmware
lt *..5.1.12 - ui/unifi_cloud_gateway_ultra_firmware
lt *..5.1.12 - ui/unifi_cloud_gateway_max_firmware
lt *..5.1.12 - ui/unifi_cloud_gateway_fiber_firmware
lt *..5.1.12 - ui/unifi_dream_router_5g_max_firmware
lt *..5.1.12 - ui/enterprise_network_video_recorder_core_firmware
lt *..5.1.12 - ui/unifi_cloud_key_plus_firmware
lt *..5.1.12 - ui/unifi_cloudkey_firmware
lt *..5.1.12 - ui/unifi_cloudkey_enterprise_firmware
lt *..5.1.12 - ui/unifi_network_video_recorder_g2_firmware
lt *..5.1.12 - ui/unifi_network_video_recorder_g2_pro_firmware
lt *..5.1.12 - ui/unifi_dream_machine_beast_firmware
lt *..5.1.11 - ui/unas_2_firmware
lt *..5.1.10 - ui/unas_4_firmware
lt *..5.1.10 - ui/unas_pro_firmware
lt *..5.1.10 - ui/unas_pro_4_firmware
lt *..5.1.10 - ui/unas_pro_8_firmware
lt *..5.1.10
Response & Mitigation
Why act now?
Prioritisation rationale
CVE-2026-34908 carries a CVSS v3 score of 10.0 (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) and sits at the 99.7th EPSS percentile, meaning virtually no comparable vulnerability has a higher exploitation probability. The unauthenticated, network-accessible attack path with a full scope change makes this a critical risk for any organisation using UniFi OS devices as network gateways or firewall platforms — a deployment pattern common in NIS2-regulated sectors such as energy, healthcare, and industrial control environments. Successful exploitation allows an attacker to alter network configuration without any prior credentials, potentially dismantling segmentation controls, VPN policies, and access rules across the entire network. Although CISA has not flagged known ransomware campaign use at this time, the ability to establish persistence and enable lateral movement represents a severe secondary risk; organisations with internet-exposed management interfaces must treat this as a P1 incident and patch or isolate immediately.
Runbook · Step 1
Immediate response (0-24 h)
- Apply vendor patch immediately: Ubiquiti has released firmware updates for all affected platforms. Target versions are above UniFi OS Server 5.0.8 and device firmware 5.1.12 — verify exact version numbers in the Ubiquiti Security Advisory and deploy via the UniFi Network Application update menu or the UI console without delay.
- Isolate management interfaces at the network layer: Move all affected UniFi OS devices (Dream Machine family, Dream Wall, Cloud Gateway Industrial, Enterprise Fortress Gateway) into a dedicated management VLAN, or tighten existing ACLs so that only authorised administrator workstations can reach TCP 443 (UI console) and TCP 22 (SSH).
- Disable cloud remote access if not operationally required: Temporarily turn off remote access via
unifi.ui.comunder UniFi OS → System → Remote Access to eliminate the internet-facing attack surface until the patch is confirmed deployed. - Invalidate all active sessions and rotate credentials: After patching, terminate all active admin sessions, rotate API keys and tokens, and reset passwords for every local and cloud account that had access to affected devices.
- Inventory all affected instances: Enumerate every UniFi OS device running firmware ≤ 5.1.12 or OS Server ≤ 5.0.8 (network scan on TCP 443 with service fingerprinting, or via
ubnt-tools) and prioritise patching by exposure level — internet-facing first.
Runbook · Step 2
Mitigation layers
- L2/L3 network segmentation: Restrict management interfaces to a dedicated out-of-band management VLAN; enforce a full deny rule between production VLANs and the management VLAN at the firewall level.
- Firewall ACLs on management ports: Limit inbound traffic on TCP 443, TCP 8443, TCP 22, and UDP 3478 (STUN) to an explicit allowlist of administrator source IPs; block all other sources with an explicit deny entry.
- IPS/IDS rule activation: On upstream IPS platforms (Suricata, Snort), enable rules alerting on unexpected POST/PUT/DELETE requests to
/api/and/proxy/network/api/originating from non-administrative source IPs; set a low threshold for HTTP 4xx responses on these endpoints. - Least-privilege IAM for UniFi accounts: Reduce the number of administrator-role accounts to the operational minimum; enforce read-only roles for monitoring accounts; enable multi-factor authentication (TOTP) for all admin accounts.
- Cloud console IP allowlisting: If cloud access cannot be disabled, configure IP allowlisting in the Ubiquiti account settings and enable geo-blocking for regions where no administrative access is expected.
Runbook · Step 3
Detection rules
- Web server access log (nginx/UniFi OS): Anomalous PUT/PATCH/DELETE requests to
/api/or/proxy/network/api/from source IPs outside the management subnet — SPL snippet:index=proxy_logs uri_path="/api/*" (method=PUT OR method=PATCH OR method=DELETE) NOT src_ip IN (management_subnet) | stats count by src_ip, uri_path - Network telemetry (Zeek/Suricata): TCP 443 or TCP 8443 connections to UniFi OS devices originating from hosts outside the management VLAN; alert on sessions lasting > 60 s with > 50 kB data transfer where no prior authentication handshake is observed.
- Syslog / UniFi OS audit log: Configuration change events (
cfg_changeoradmin_action) performed by accounts created within the last 24 hours or accounts with no prior login history — Sigma shape:title: UniFi OS Unauthorized Config Change | logsource: product: unifi_os | detection: keywords: ['cfg_change', 'admin_action'] filter: account_age < 24h - EDR/endpoint (if UniFi OS host is accessible): Unexpected child processes spawned by
unifi-osormcad; specifically shell execution (/bin/sh,/bin/bash) as a child of the UniFi service process — Sysmon EID 1 or auditdEXECVEwith the UniFi process as parent PID. - Authentication log: Multiple successful logins from different source IPs within a short window (< 5 min) for the same admin account — indicative of session hijacking or token reuse.
Description
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized changes to the system.
Affected operating systems
other
ui / enterprise_fortress_gateway_firmware
other
ui / enterprise_network_video_recorder_core_firmware
other
ui / enterprise_network_video_recorder_firmware
other
ui / unas_2_firmware
other
ui / unas_4_firmware
other
ui / unas_pro_4_firmware
other
ui / unas_pro_8_firmware
other
ui / unas_pro_firmware
other
ui / unifi_cloud_gateway_fiber_firmware
other
ui / unifi_cloud_gateway_industrial_firmware
other
ui / unifi_cloud_gateway_max_firmware
other
ui / unifi_cloud_gateway_ultra_firmware
other
ui / unifi_cloud_key_plus_firmware
other
ui / unifi_cloudkey_enterprise_firmware
other
ui / unifi_cloudkey_firmware
other
ui / unifi_dream_machine_beast_firmware
other
ui / unifi_dream_machine_firmware
other
ui / unifi_dream_machine_pro_firmware
other
ui / unifi_dream_machine_pro_max_firmware
other
ui / unifi_dream_machine_special_edition_firmware
other
ui / unifi_dream_router_5g_max_firmware
other
ui / unifi_dream_router_7_firmware
other
ui / unifi_dream_router_firmware
other
ui / unifi_dream_wall_firmware
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
5.0.8fixed from 5.0.8Metrics
Show all metrics
Weakness classes (CWE)
CWE-284Pillar
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
cwe.mitre.org →
Public exploit references
Public proof-of-concepts and detection templates for this vulnerability. Maturity ranges from reported PoCs through working detection scripts up to fully weaponized exploit modules. NEOSEC mirrors the code internally for forensic analysis; externally we only link to the original sources.
References & sources
- https://community.ui.com/releases/Security-Advisory-Bulletin-064-064/84811c09-4cf4-42ab-bd61-cc994445963b
- https://www.pwndefend.com/2026/06/09/cve-2026-34910-exploitation-itw-building-a-botnet-mirai/third-party-advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-34908government-resource
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- CVE Translated2026-07-23 16:10 UTC· nvd@nist.gov
- Translation: Title: varios productos de Ubiquiti, Description: Un actor malicioso con acceso a la red podría explotar una vulnerabilidad de control de acceso inadecuado encontrada en dispositivos UniFi OS para realizar cambios no autorizados en el sistema.
- Initial Analysis2026-06-24 14:50 UTC· nvd@nist.gov
- CPE Configuration: OR *cpe:2.3:a:ui:unifi_os_server:*:*:*:*:*:*:*:* versions up to (excluding) 5.0.8
- CPE Configuration: AND OR *cpe:2.3:o:ui:unifi_cloud_gateway_industrial_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 5.1.12 OR cpe:2.3:h:ui:unifi_cloud_gateway_industrial:-:*:*:*:*:*:*:*
- CPE Configuration: AND OR *cpe:2.3:o:ui:unifi_dream_machine_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 5.1.12 OR cpe:2.3:h:ui:unifi_dream_machine:-:*:*:*:*:*:*:*
- CPE Configuration: AND OR *cpe:2.3:o:ui:unifi_dream_machine_pro_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 5.1.12 OR cpe:2.3:h:ui:unifi_dream_machine_pro:-:*:*:*:*:*:*:*
- CVE Modified2026-06-24 05:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- SSVC: {"id":"CVE-2026-34908","role":"CISA Coordinator","options":[{"exploitation":"active"},{"automatable":"yes"},{"technic… → {"id":"CVE-2026-34908","role":"CISA Coordinator","options":[{"exploitation":"active"},{"automatable":"yes"},{"technic…
- CVE CISA KEV Update2026-06-23 19:00 UTC· 9119a7d8-5eab-497f-8521-727c672e3725
- Date Added: 2026-06-23
- Due Date: 2026-06-23
- Required Action: 2026-06-23
- Vulnerability Name: 2026-06-23
- CVE Modified2026-06-23 18:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- Reference: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-34908
- Reference: https://www.pwndefend.com/2026/06/09/cve-2026-34910-exploitation-itw-building-a-botnet-mirai/
- SSVC: {"id":"CVE-2026-34908","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"yes"},{"technical… → {"id":"CVE-2026-34908","role":"CISA Coordinator","options":[{"exploitation":"active"},{"automatable":"yes"},{"technic…
Linked advisories
- sans-newsbites-mail2026-07-02 00:00 UTCUbiquiti Patches Critical UniFi Vulnerabilities
- sans-newsbites-mail2026-06-24 00:00 UTCKEV: Lantronix, Ubiquiti UniFi OS, PTC Windchill and FlexPLM, and Cisco Unified Communications Manager
- sans-newsbites-mail2026-05-21 00:00 UTCPatch UniFi OS for Three CVSS 10.0 Flaws