CVE-2026-34909
Ubiquiti UniFi OS Path Traversal Vulnerability
Description
A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to access an underlying account.
Description as published by the source, in English.
Key facts
- Published
- 2026-05-22
- Last modified
- 2026-07-23
- Assigned by
- support@hackerone.com
- CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H- Scored by
- support@hackerone.com
- Probability of exploitation
-
62.8 %
higher than 99 %
of all known vulnerabilities
EPSS, next 30 days, model v2026.06.15 - Fix available
- Yes, see references
Actively exploited
CISA added this vulnerability to the Known Exploited Vulnerabilities catalogue on 2026-06-23, with a remediation deadline of 2026-06-26 for US federal agencies.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Affected products
| Vendor | Product | Versions | Status |
|---|---|---|---|
| Ui | Enterprise Fortress Gateway | all versions listed | Not affected |
| Ui | Enterprise Fortress Gateway Firmware | < 5.1.12 | Affected |
| Ui | Enterprise Network Video Recorder | all versions listed | Not affected |
| Ui | Enterprise Network Video Recorder Core | all versions listed | Not affected |
| Ui | Enterprise Network Video Recorder Core Firmware | < 5.1.12 | Affected |
| Ui | Enterprise Network Video Recorder Firmware | < 5.1.12 | Affected |
| Ui | Unas 2 | all versions listed | Not affected |
| Ui | Unas 2 Firmware | < 5.1.10 | Affected |
| Ui | Unas 4 | all versions listed | Not affected |
| Ui | Unas 4 Firmware | < 5.1.10 | Affected |
| Ui | Unas Pro | all versions listed | Not affected |
| Ui | Unas Pro 4 | all versions listed | Not affected |
| Ui | Unas Pro 4 Firmware | < 5.1.10 | Affected |
| Ui | Unas Pro 8 | all versions listed | Not affected |
| Ui | Unas Pro 8 Firmware | < 5.1.10 | Affected |
| Ui | Unas Pro Firmware | < 5.1.10 | Affected |
| Ui | Unifi Cloud Gateway Fiber | all versions listed | Not affected |
| Ui | Unifi Cloud Gateway Fiber Firmware | < 5.1.12 | Affected |
| Ui | Unifi Cloud Gateway Industrial | all versions listed | Not affected |
| Ui | Unifi Cloud Gateway Industrial Firmware | < 5.1.12 | Affected |
| Ui | Unifi Cloud Gateway Max | all versions listed | Not affected |
| Ui | Unifi Cloud Gateway Max Firmware | < 5.1.12 | Affected |
| Ui | Unifi Cloud Gateway Ultra | all versions listed | Not affected |
| Ui | Unifi Cloud Gateway Ultra Firmware | < 5.1.12 | Affected |
| Ui | Unifi Cloud Key Plus | all versions listed | Not affected |
| Ui | Unifi Cloud Key Plus Firmware | < 5.1.12 | Affected |
| Ui | Unifi Cloudkey | all versions listed | Not affected |
| Ui | Unifi Cloudkey Enterprise | all versions listed | Not affected |
| Ui | Unifi Cloudkey Enterprise Firmware | < 5.1.12 | Affected |
| Ui | Unifi Cloudkey Firmware | < 5.1.12 | Affected |
| Ui | Unifi Dream Machine | all versions listed | Not affected |
| Ui | Unifi Dream Machine Beast | all versions listed | Not affected |
| Ui | Unifi Dream Machine Beast Firmware | < 5.1.11 | Affected |
| Ui | Unifi Dream Machine Firmware | < 5.1.12 | Affected |
| Ui | Unifi Dream Machine Pro | all versions listed | Not affected |
| Ui | Unifi Dream Machine Pro Firmware | < 5.1.12 | Affected |
| Ui | Unifi Dream Machine Pro Max | all versions listed | Not affected |
| Ui | Unifi Dream Machine Pro Max Firmware | < 5.1.12 | Affected |
| Ui | Unifi Dream Machine Special Edition | all versions listed | Not affected |
| Ui | Unifi Dream Machine Special Edition Firmware | < 5.1.12 | Affected |
| Ui | Unifi Dream Router | all versions listed | Not affected |
| Ui | Unifi Dream Router 5g Max | all versions listed | Not affected |
| Ui | Unifi Dream Router 5g Max Firmware | < 5.1.12 | Affected |
| Ui | Unifi Dream Router 7 | all versions listed | Not affected |
| Ui | Unifi Dream Router 7 Firmware | < 5.1.12 | Affected |
| Ui | Unifi Dream Router Firmware | < 5.1.12 | Affected |
| Ui | Unifi Dream Wall | all versions listed | Not affected |
| Ui | Unifi Dream Wall Firmware | < 5.1.12 | Affected |
| Ui | Unifi Express | all versions listed | Not affected |
| Ui | Unifi Express 7 | all versions listed | Not affected |
| Ui | Unifi Express 7 Firmware | < 5.1.12 | Affected |
| Ui | Unifi Express Firmware | < 4.0.14 | Affected |
| Ui | Unifi Network Video Recorder | all versions listed | Not affected |
| Ui | Unifi Network Video Recorder Firmware | < 5.1.12 | Affected |
| Ui | Unifi Network Video Recorder G2 | all versions listed | Not affected |
| Ui | Unifi Network Video Recorder G2 Firmware | < 5.1.12 | Affected |
| Ui | Unifi Network Video Recorder G2 Pro | all versions listed | Not affected |
| Ui | Unifi Network Video Recorder G2 Pro Firmware | < 5.1.12 | Affected |
| Ui | Unifi Network Video Recorder Instant | all versions listed | Not affected |
| Ui | Unifi Network Video Recorder Instant Firmware | < 5.1.12 | Affected |
Weakness type
-
CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special ele…
References
- https://community.ui.com/releases/Security-Advisory-Bulletin-064-064/84811c09-4cf4-42ab-b…
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-34909
- https://www.pwndefend.com/2026/06/09/cve-2026-34910-exploitation-itw-building-a-botnet-mi…
Does this affect you?
A vulnerability matters only if you run the product, in an affected version, somewhere an attacker can reach.