CVE-2026-34909
unifi_os_server: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CVE-2026-34909)
Affected
- ui/unifi_os_server
lt *..5.0.8 - ui/unifi_cloud_gateway_industrial_firmware
lt *..5.1.12 - ui/unifi_dream_machine_firmware
lt *..5.1.12 - ui/unifi_dream_machine_pro_firmware
lt *..5.1.12 - ui/unifi_dream_machine_special_edition_firmware
lt *..5.1.12 - ui/unifi_dream_machine_pro_max_firmware
lt *..5.1.12 - ui/enterprise_fortress_gateway_firmware
lt *..5.1.12 - ui/unifi_dream_wall_firmware
lt *..5.1.12 - ui/unifi_dream_router_firmware
lt *..5.1.12 - ui/unifi_dream_router_7_firmware
lt *..5.1.12 - ui/unifi_express_7_firmware
lt *..5.1.12 - ui/unifi_network_video_recorder_firmware
lt *..5.1.12 - ui/unifi_network_video_recorder_pro_firmware
lt *..5.1.12 - ui/unifi_network_video_recorder_instant_firmware
lt *..5.1.12 - ui/enterprise_network_video_recorder_firmware
lt *..5.1.12 - ui/unifi_cloud_gateway_ultra_firmware
lt *..5.1.12 - ui/unifi_cloud_gateway_max_firmware
lt *..5.1.12 - ui/unifi_cloud_gateway_fiber_firmware
lt *..5.1.12 - ui/unifi_dream_router_5g_max_firmware
lt *..5.1.12 - ui/enterprise_network_video_recorder_core_firmware
lt *..5.1.12 - ui/unifi_cloud_key_plus_firmware
lt *..5.1.12 - ui/unifi_cloudkey_firmware
lt *..5.1.12 - ui/unifi_cloudkey_enterprise_firmware
lt *..5.1.12 - ui/unifi_network_video_recorder_g2_firmware
lt *..5.1.12 - ui/unifi_network_video_recorder_g2_pro_firmware
lt *..5.1.12 - ui/unifi_dream_machine_beast_firmware
lt *..5.1.11 - ui/unas_2_firmware
lt *..5.1.10 - ui/unas_4_firmware
lt *..5.1.10 - ui/unas_pro_firmware
lt *..5.1.10 - ui/unas_pro_4_firmware
lt *..5.1.10 - ui/unas_pro_8_firmware
lt *..5.1.10 - ui/unifi_express_firmware
lt *..4.0.14
Response & Mitigation
Why act now?
Prioritisation rationale
CVE-2026-34909 carries a CVSS v3 score of 10.0 (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) — the maximum possible — and sits at the 99.2nd EPSS percentile, indicating an exceptionally high probability of active exploitation. The attack requires no authentication, no user interaction, and no special conditions, meaning any network-reachable UniFi OS device is fully exploitable by an unauthenticated attacker who can read or manipulate underlying OS files to gain account access. For NIS2-scoped organisations — particularly those using UniFi OS devices as core network gateways or in managed-service environments — a successful compromise can serve as a pivot point for lateral movement across the entire managed network. Although CISA has not flagged known ransomware campaign use, the combination of a perfect CVSS score, zero authentication requirement, and the broad deployment of UniFi OS in enterprise and KRITIS environments makes this a patch-immediately priority with no tolerance for delay.
Runbook · Step 1
Immediate response (0-24 h)
- Apply vendor patch immediately: Ubiquiti has released firmware updates for all affected platforms. Target versions: UniFi OS Server > 5.0.8; all UniFi Dream Machine, Cloud Gateway Industrial, Dream Wall, and Enterprise Fortress Gateway firmware variants > 5.1.12. Verify exact build numbers in the Ubiquiti Security Advisory and deploy via the UniFi Network Controller update interface or the UI console.
- Restrict management interface access: Ensure the UniFi OS web interface (default TCP 443 / 8443) is reachable only from dedicated management VLANs. Audit firewall rules immediately and block all non-authorised source IP ranges.
- Inventory all affected devices: Enumerate every UniFi OS device (Dream Machine series, Dream Wall, Cloud Gateway Industrial, Enterprise Fortress Gateway) in your environment and compare running firmware versions against the vulnerable thresholds 5.0.8 / 5.1.12.
- Audit local accounts and SSH keys: On each affected device, review local user accounts and SSH
authorized_keysfiles for unauthorised entries; disable suspicious accounts and rotate all credentials immediately. - Preserve forensic telemetry: Confirm syslog forwarding to your SIEM is active before patching, so pre-patch log data is not lost for post-incident analysis.
Runbook · Step 2
Mitigation layers
- Network segmentation (top priority): Move UniFi OS management interfaces into an isolated out-of-band management VLAN with no direct internet exposure. Enforce access exclusively via jump host or VPN with MFA.
- WAF/IPS rule: Block inbound HTTP requests containing path traversal patterns (
../,..%2F,..%5C, double-encoded%252F) targeting ports 443/8443. Suggested Suricata signature:alert http any any -> $MGMT_NET [443,8443] (msg:"CVE-2026-34909 Path Traversal attempt"; content:"../"; http_uri; nocase; sid:2026349090; rev:1;) - Least-privilege / IAM hardening: Minimise the number of local admin accounts on UniFi OS; enforce Ubiquiti SSO with MFA for all administrative access; restrict API token scopes to the minimum required.
- File integrity monitoring: Where device access permits, monitor critical system files —
/etc/passwd,/etc/shadow, and all SSHauthorized_keysfiles — for unexpected modifications using a file integrity monitoring solution. - Disable remote management temporarily: If immediate patching is not feasible, disable UI Remote Access (cloud.ui.com) in UniFi OS settings until the firmware update can be applied.
Runbook · Step 3
Detection rules
- Web server access logs (nginx/UniFi OS): Alert on requests containing path traversal sequences in the URI. SPL snippet:
index=unifi sourcetype=access_log uri="*../*" OR uri="*%2e%2e%2f*" | stats count by src_ip, uri - Auditd / file access monitoring: Watch for unexpected read access to
/etc/passwd,/etc/shadow, or~/.ssh/authorized_keysby the web server process (unifi-os,nginx). Auditd rule:-w /etc/passwd -p r -k cve_2026_34909 - New local account creation: Monitor for new system account creation on UniFi OS devices following a potential exploitation window. Track auditd syscalls for
useradd/adduseror direct modifications to/etc/passwdtagged withkey=cve_2026_34909. - Network telemetry (Zeek/Suricata): Flag HTTP 200 responses to requests containing
../patterns against management ports originating from non-management or external source IPs. Zeek HTTP log filter:http.log | where uri contains ".." && resp_mime_types contains "text". - Post-exploitation SSH correlation: Correlate successful or failed SSH logins on UniFi OS devices from unknown source IPs occurring within a short time window (< 5 minutes) after observed path traversal requests.
Description
A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to access an underlying account.
Affected operating systems
other
ui / enterprise_fortress_gateway_firmware
other
ui / enterprise_network_video_recorder_core_firmware
other
ui / enterprise_network_video_recorder_firmware
other
ui / unas_2_firmware
other
ui / unas_4_firmware
other
ui / unas_pro_4_firmware
other
ui / unas_pro_8_firmware
other
ui / unas_pro_firmware
other
ui / unifi_cloud_gateway_fiber_firmware
other
ui / unifi_cloud_gateway_industrial_firmware
other
ui / unifi_cloud_gateway_max_firmware
other
ui / unifi_cloud_gateway_ultra_firmware
other
ui / unifi_cloud_key_plus_firmware
other
ui / unifi_cloudkey_enterprise_firmware
other
ui / unifi_cloudkey_firmware
other
ui / unifi_dream_machine_beast_firmware
other
ui / unifi_dream_machine_firmware
other
ui / unifi_dream_machine_pro_firmware
other
ui / unifi_dream_machine_pro_max_firmware
other
ui / unifi_dream_machine_special_edition_firmware
other
ui / unifi_dream_router_5g_max_firmware
other
ui / unifi_dream_router_7_firmware
other
ui / unifi_dream_router_firmware
other
ui / unifi_dream_wall_firmware
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
5.0.8fixed from 5.0.8Metrics
Show all metrics
Weakness classes (CWE)
CWE-22Base
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
cwe.mitre.org →
Public exploit references
Public proof-of-concepts and detection templates for this vulnerability. Maturity ranges from reported PoCs through working detection scripts up to fully weaponized exploit modules. NEOSEC mirrors the code internally for forensic analysis; externally we only link to the original sources.
References & sources
- https://community.ui.com/releases/Security-Advisory-Bulletin-064-064/84811c09-4cf4-42ab-bd61-cc994445963b
- https://www.pwndefend.com/2026/06/09/cve-2026-34910-exploitation-itw-building-a-botnet-mirai/third-party-advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-34909government-resource
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- CVE Translated2026-07-23 16:10 UTC· nvd@nist.gov
- Translation: Title: varios productos de Ubiquiti, Description: Un actor malicioso con acceso a la red podría explotar una vulnerabilidad de salto de ruta encontrada en dispositivos UniFi OS para acceder a archivos en el sistema subyacente que podrían ser manipulados para acceder a una cuenta subyacente.
- Initial Analysis2026-06-24 14:49 UTC· nvd@nist.gov
- CPE Configuration: OR *cpe:2.3:a:ui:unifi_os_server:*:*:*:*:*:*:*:* versions up to (excluding) 5.0.8
- CPE Configuration: AND OR *cpe:2.3:o:ui:unifi_cloud_gateway_industrial_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 5.1.12 OR cpe:2.3:h:ui:unifi_cloud_gateway_industrial:-:*:*:*:*:*:*:*
- CPE Configuration: AND OR *cpe:2.3:o:ui:unifi_dream_machine_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 5.1.12 OR cpe:2.3:h:ui:unifi_dream_machine:-:*:*:*:*:*:*:*
- CPE Configuration: AND OR *cpe:2.3:o:ui:unifi_dream_machine_pro_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 5.1.12 OR cpe:2.3:h:ui:unifi_dream_machine_pro:-:*:*:*:*:*:*:*
- CVE Modified2026-06-24 05:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- SSVC: {"id":"CVE-2026-34909","role":"CISA Coordinator","options":[{"exploitation":"active"},{"automatable":"yes"},{"technic… → {"id":"CVE-2026-34909","role":"CISA Coordinator","options":[{"exploitation":"active"},{"automatable":"yes"},{"technic…
- CVE CISA KEV Update2026-06-23 19:00 UTC· 9119a7d8-5eab-497f-8521-727c672e3725
- Date Added: 2026-06-23
- Due Date: 2026-06-23
- Required Action: 2026-06-23
- Vulnerability Name: 2026-06-23
- CVE Modified2026-06-23 18:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- Reference: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-34909
- Reference: https://www.pwndefend.com/2026/06/09/cve-2026-34910-exploitation-itw-building-a-botnet-mirai/
- SSVC: {"id":"CVE-2026-34909","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"yes"},{"technical… → {"id":"CVE-2026-34909","role":"CISA Coordinator","options":[{"exploitation":"active"},{"automatable":"yes"},{"technic…
Linked advisories
- sans-newsbites-mail2026-07-02 00:00 UTCUbiquiti Patches Critical UniFi Vulnerabilities
- sans-newsbites-mail2026-06-24 00:00 UTCKEV: Lantronix, Ubiquiti UniFi OS, PTC Windchill and FlexPLM, and Cisco Unified Communications Manager
- sans-newsbites-mail2026-05-21 00:00 UTCPatch UniFi OS for Three CVSS 10.0 Flaws