Path Traversal Vulnerability in UniFi OS Devices by Ubiquiti
CVE-2026-34909

10CRITICAL

Key Information:

Vendor
CVE Published:
22 May 2026

Badges

📈 Score: 1,260👾 Exploit Exists🟣 EPSS 65%🦅 CISA Reported

What is CVE-2026-34909?

CVE-2026-34909 is a path traversal vulnerability identified in UniFi OS devices produced by Ubiquiti Inc. These devices serve as a vital part of networking infrastructure in various environments, allowing for management and monitoring of network resources. This vulnerability enables a malicious actor who has network access to navigate through the file system of the device by exploiting improper input validation mechanisms. Consequently, the attacker can potentially access files that would typically be restricted, leading to unauthorized file manipulation and access to sensitive account information. The ramifications of such a breach could significantly undermine system integrity, confidentiality, and operational continuity for organizations relying on UniFi OS devices.

Potential impact of CVE-2026-34909

  1. Unauthorized Data Access: Attackers could exploit this vulnerability to gain access to sensitive files on the UniFi OS devices, leading to potential data leaks and breaches of confidential information.

  2. System Compromise: By manipulating files accessible through this vulnerability, a malicious actor may escalate privileges or compromise the device itself, resulting in wider network implications and a cascading effect on connected systems.

  3. Increased Risk of Further Attacks: The ability to traverse file paths may grant attackers the opportunity to deploy additional exploits or malicious software, raising the overall security risk for organizations and potentially serving as a gateway for ransomware or other cyber threats.

CISA has reported CVE-2026-34909

CISA provides regional cyber and physical services to support security and resilience across the United States. CISA monitor the most dangerious vulnerabilities and have identifed CVE-2026-34909 as being exploited but is not known by the CISA to be used in ransomware campaigns. This is subject to change at pace

The CISA's recommendation is: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Affected Version(s)

EFG 0 < 5.1.12

ENVR 0 < 5.1.12

ENVR-Core 0 < 5.1.12

References

EPSS Score

65% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • 🦅

    CISA Reported

  • Vulnerability published

  • Vulnerability Reserved

.