CVE-2026-34909

unifi_os_server: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CVE-2026-34909)

Affected

  • ui/unifi_os_server lt *..5.0.8
  • ui/unifi_cloud_gateway_industrial_firmware lt *..5.1.12
  • ui/unifi_dream_machine_firmware lt *..5.1.12
  • ui/unifi_dream_machine_pro_firmware lt *..5.1.12
  • ui/unifi_dream_machine_special_edition_firmware lt *..5.1.12
  • ui/unifi_dream_machine_pro_max_firmware lt *..5.1.12
  • ui/enterprise_fortress_gateway_firmware lt *..5.1.12
  • ui/unifi_dream_wall_firmware lt *..5.1.12
  • ui/unifi_dream_router_firmware lt *..5.1.12
  • ui/unifi_dream_router_7_firmware lt *..5.1.12
  • ui/unifi_express_7_firmware lt *..5.1.12
  • ui/unifi_network_video_recorder_firmware lt *..5.1.12
  • ui/unifi_network_video_recorder_pro_firmware lt *..5.1.12
  • ui/unifi_network_video_recorder_instant_firmware lt *..5.1.12
  • ui/enterprise_network_video_recorder_firmware lt *..5.1.12
  • ui/unifi_cloud_gateway_ultra_firmware lt *..5.1.12
  • ui/unifi_cloud_gateway_max_firmware lt *..5.1.12
  • ui/unifi_cloud_gateway_fiber_firmware lt *..5.1.12
  • ui/unifi_dream_router_5g_max_firmware lt *..5.1.12
  • ui/enterprise_network_video_recorder_core_firmware lt *..5.1.12
  • ui/unifi_cloud_key_plus_firmware lt *..5.1.12
  • ui/unifi_cloudkey_firmware lt *..5.1.12
  • ui/unifi_cloudkey_enterprise_firmware lt *..5.1.12
  • ui/unifi_network_video_recorder_g2_firmware lt *..5.1.12
  • ui/unifi_network_video_recorder_g2_pro_firmware lt *..5.1.12
  • ui/unifi_dream_machine_beast_firmware lt *..5.1.11
  • ui/unas_2_firmware lt *..5.1.10
  • ui/unas_4_firmware lt *..5.1.10
  • ui/unas_pro_firmware lt *..5.1.10
  • ui/unas_pro_4_firmware lt *..5.1.10
  • ui/unas_pro_8_firmware lt *..5.1.10
  • ui/unifi_express_firmware lt *..4.0.14

Response & Mitigation

Why act now?

Prioritisation rationale

CVE-2026-34909 carries a CVSS v3 score of 10.0 (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) — the maximum possible — and sits at the 99.2nd EPSS percentile, indicating an exceptionally high probability of active exploitation. The attack requires no authentication, no user interaction, and no special conditions, meaning any network-reachable UniFi OS device is fully exploitable by an unauthenticated attacker who can read or manipulate underlying OS files to gain account access. For NIS2-scoped organisations — particularly those using UniFi OS devices as core network gateways or in managed-service environments — a successful compromise can serve as a pivot point for lateral movement across the entire managed network. Although CISA has not flagged known ransomware campaign use, the combination of a perfect CVSS score, zero authentication requirement, and the broad deployment of UniFi OS in enterprise and KRITIS environments makes this a patch-immediately priority with no tolerance for delay.

Runbook · Step 1

Immediate response (0-24 h)

  • Apply vendor patch immediately: Ubiquiti has released firmware updates for all affected platforms. Target versions: UniFi OS Server > 5.0.8; all UniFi Dream Machine, Cloud Gateway Industrial, Dream Wall, and Enterprise Fortress Gateway firmware variants > 5.1.12. Verify exact build numbers in the Ubiquiti Security Advisory and deploy via the UniFi Network Controller update interface or the UI console.
  • Restrict management interface access: Ensure the UniFi OS web interface (default TCP 443 / 8443) is reachable only from dedicated management VLANs. Audit firewall rules immediately and block all non-authorised source IP ranges.
  • Inventory all affected devices: Enumerate every UniFi OS device (Dream Machine series, Dream Wall, Cloud Gateway Industrial, Enterprise Fortress Gateway) in your environment and compare running firmware versions against the vulnerable thresholds 5.0.8 / 5.1.12.
  • Audit local accounts and SSH keys: On each affected device, review local user accounts and SSH authorized_keys files for unauthorised entries; disable suspicious accounts and rotate all credentials immediately.
  • Preserve forensic telemetry: Confirm syslog forwarding to your SIEM is active before patching, so pre-patch log data is not lost for post-incident analysis.

Runbook · Step 2

Mitigation layers

  • Network segmentation (top priority): Move UniFi OS management interfaces into an isolated out-of-band management VLAN with no direct internet exposure. Enforce access exclusively via jump host or VPN with MFA.
  • WAF/IPS rule: Block inbound HTTP requests containing path traversal patterns (../, ..%2F, ..%5C, double-encoded %252F) targeting ports 443/8443. Suggested Suricata signature: alert http any any -> $MGMT_NET [443,8443] (msg:"CVE-2026-34909 Path Traversal attempt"; content:"../"; http_uri; nocase; sid:2026349090; rev:1;)
  • Least-privilege / IAM hardening: Minimise the number of local admin accounts on UniFi OS; enforce Ubiquiti SSO with MFA for all administrative access; restrict API token scopes to the minimum required.
  • File integrity monitoring: Where device access permits, monitor critical system files — /etc/passwd, /etc/shadow, and all SSH authorized_keys files — for unexpected modifications using a file integrity monitoring solution.
  • Disable remote management temporarily: If immediate patching is not feasible, disable UI Remote Access (cloud.ui.com) in UniFi OS settings until the firmware update can be applied.

Runbook · Step 3

Detection rules

  • Web server access logs (nginx/UniFi OS): Alert on requests containing path traversal sequences in the URI. SPL snippet: index=unifi sourcetype=access_log uri="*../*" OR uri="*%2e%2e%2f*" | stats count by src_ip, uri
  • Auditd / file access monitoring: Watch for unexpected read access to /etc/passwd, /etc/shadow, or ~/.ssh/authorized_keys by the web server process (unifi-os, nginx). Auditd rule: -w /etc/passwd -p r -k cve_2026_34909
  • New local account creation: Monitor for new system account creation on UniFi OS devices following a potential exploitation window. Track auditd syscalls for useradd/adduser or direct modifications to /etc/passwd tagged with key=cve_2026_34909.
  • Network telemetry (Zeek/Suricata): Flag HTTP 200 responses to requests containing ../ patterns against management ports originating from non-management or external source IPs. Zeek HTTP log filter: http.log | where uri contains ".." && resp_mime_types contains "text".
  • Post-exploitation SSH correlation: Correlate successful or failed SSH logins on UniFi OS devices from unknown source IPs occurring within a short time window (< 5 minutes) after observed path traversal requests.

Description

A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to access an underlying account.

Affected operating systems

  • other

    ui / enterprise_fortress_gateway_firmware

  • other

    ui / enterprise_network_video_recorder_core_firmware

  • other

    ui / enterprise_network_video_recorder_firmware

  • other

    ui / unas_2_firmware

  • other

    ui / unas_4_firmware

  • other

    ui / unas_pro_4_firmware

  • other

    ui / unas_pro_8_firmware

  • other

    ui / unas_pro_firmware

  • other

    ui / unifi_cloud_gateway_fiber_firmware

  • other

    ui / unifi_cloud_gateway_industrial_firmware

  • other

    ui / unifi_cloud_gateway_max_firmware

  • other

    ui / unifi_cloud_gateway_ultra_firmware

  • other

    ui / unifi_cloud_key_plus_firmware

  • other

    ui / unifi_cloudkey_enterprise_firmware

  • other

    ui / unifi_cloudkey_firmware

  • other

    ui / unifi_dream_machine_beast_firmware

  • other

    ui / unifi_dream_machine_firmware

  • other

    ui / unifi_dream_machine_pro_firmware

  • other

    ui / unifi_dream_machine_pro_max_firmware

  • other

    ui / unifi_dream_machine_special_edition_firmware

  • other

    ui / unifi_dream_router_5g_max_firmware

  • other

    ui / unifi_dream_router_7_firmware

  • other

    ui / unifi_dream_router_firmware

  • other

    ui / unifi_dream_wall_firmware

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

uiunifi_os_server
5.0.8fixed from 5.0.8

Metrics

10.0
Source: nvd-v3
77.8 %
High — this CVE ranks above the median of all CVEs scored today (rank ≥ 36%).
Actively exploited
Show all metrics
Severity
critical
actively exploited (KEV)
1.8 %
Moderate — model estimates 1-10% exploitation likelihood.
Published
2026-06-23 00:00 UTC
CWE-22

Weakness classes (CWE)

  • CWE-22Base

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

    The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

    cwe.mitre.org →

Public exploit references

Public proof-of-concepts and detection templates for this vulnerability. Maturity ranges from reported PoCs through working detection scripts up to fully weaponized exploit modules. NEOSEC mirrors the code internally for forensic analysis; externally we only link to the original sources.

References & sources

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Translated2026-07-23 16:10 UTC· nvd@nist.gov
    • Translation: Title: varios productos de Ubiquiti, Description: Un actor malicioso con acceso a la red podría explotar una vulnerabilidad de salto de ruta encontrada en dispositivos UniFi OS para acceder a archivos en el sistema subyacente que podrían ser manipulados para acceder a una cuenta subyacente.
  2. Initial Analysis2026-06-24 14:49 UTC· nvd@nist.gov
    • CPE Configuration: OR *cpe:2.3:a:ui:unifi_os_server:*:*:*:*:*:*:*:* versions up to (excluding) 5.0.8
    • CPE Configuration: AND OR *cpe:2.3:o:ui:unifi_cloud_gateway_industrial_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 5.1.12 OR cpe:2.3:h:ui:unifi_cloud_gateway_industrial:-:*:*:*:*:*:*:*
    • CPE Configuration: AND OR *cpe:2.3:o:ui:unifi_dream_machine_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 5.1.12 OR cpe:2.3:h:ui:unifi_dream_machine:-:*:*:*:*:*:*:*
    • CPE Configuration: AND OR *cpe:2.3:o:ui:unifi_dream_machine_pro_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 5.1.12 OR cpe:2.3:h:ui:unifi_dream_machine_pro:-:*:*:*:*:*:*:*
  3. CVE Modified2026-06-24 05:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-34909","role":"CISA Coordinator","options":[{"exploitation":"active"},{"automatable":"yes"},{"technic… → {"id":"CVE-2026-34909","role":"CISA Coordinator","options":[{"exploitation":"active"},{"automatable":"yes"},{"technic…
  4. CVE CISA KEV Update2026-06-23 19:00 UTC· 9119a7d8-5eab-497f-8521-727c672e3725
    • Date Added: 2026-06-23
    • Due Date: 2026-06-23
    • Required Action: 2026-06-23
    • Vulnerability Name: 2026-06-23
  5. CVE Modified2026-06-23 18:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • Reference: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-34909
    • Reference: https://www.pwndefend.com/2026/06/09/cve-2026-34910-exploitation-itw-building-a-botnet-mirai/
    • SSVC: {"id":"CVE-2026-34909","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"yes"},{"technical… → {"id":"CVE-2026-34909","role":"CISA Coordinator","options":[{"exploitation":"active"},{"automatable":"yes"},{"technic…

Linked advisories