CVE-2026-34910
Ubiquiti UniFi OS Improper Input Validation Vulnerability
Description
A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.
Description as published by the source, in English.
Key facts
- Published
- 2026-05-22
- Last modified
- 2026-07-23
- Assigned by
- support@hackerone.com
- CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H- Scored by
- support@hackerone.com
- Probability of exploitation
-
87.0 %
among the highest of all known vulnerabilities
EPSS, next 30 days, model v2026.06.15 - Fix available
- Yes, see references
Actively exploited
CISA added this vulnerability to the Known Exploited Vulnerabilities catalogue on 2026-06-23, with a remediation deadline of 2026-06-26 for US federal agencies.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Affected products
| Vendor | Product | Versions | Status |
|---|---|---|---|
| Ui | Enterprise Fortress Gateway | all versions listed | Not affected |
| Ui | Enterprise Fortress Gateway Firmware | < 5.1.12 | Affected |
| Ui | Enterprise Network Video Recorder | all versions listed | Not affected |
| Ui | Enterprise Network Video Recorder Core | all versions listed | Not affected |
| Ui | Enterprise Network Video Recorder Core Firmware | < 5.1.12 | Affected |
| Ui | Enterprise Network Video Recorder Firmware | < 5.1.12 | Affected |
| Ui | Unas 2 | all versions listed | Not affected |
| Ui | Unas 2 Firmware | < 5.1.10 | Affected |
| Ui | Unas 4 | all versions listed | Not affected |
| Ui | Unas 4 Firmware | < 5.1.10 | Affected |
| Ui | Unas Pro | all versions listed | Not affected |
| Ui | Unas Pro 4 | all versions listed | Not affected |
| Ui | Unas Pro 4 Firmware | < 5.1.10 | Affected |
| Ui | Unas Pro 8 | all versions listed | Not affected |
| Ui | Unas Pro 8 Firmware | < 5.1.10 | Affected |
| Ui | Unas Pro Firmware | < 5.1.10 | Affected |
| Ui | Unifi Cloud Gateway Fiber | all versions listed | Not affected |
| Ui | Unifi Cloud Gateway Fiber Firmware | < 5.1.12 | Affected |
| Ui | Unifi Cloud Gateway Industrial | all versions listed | Not affected |
| Ui | Unifi Cloud Gateway Industrial Firmware | < 5.1.12 | Affected |
| Ui | Unifi Cloud Gateway Max | all versions listed | Not affected |
| Ui | Unifi Cloud Gateway Max Firmware | < 5.1.12 | Affected |
| Ui | Unifi Cloud Gateway Ultra | all versions listed | Not affected |
| Ui | Unifi Cloud Gateway Ultra Firmware | < 5.1.12 | Affected |
| Ui | Unifi Cloud Key Plus | all versions listed | Not affected |
| Ui | Unifi Cloud Key Plus Firmware | < 5.1.12 | Affected |
| Ui | Unifi Cloudkey | all versions listed | Not affected |
| Ui | Unifi Cloudkey Enterprise | all versions listed | Not affected |
| Ui | Unifi Cloudkey Enterprise Firmware | < 5.1.12 | Affected |
| Ui | Unifi Cloudkey Firmware | < 5.1.12 | Affected |
| Ui | Unifi Dream Machine | all versions listed | Not affected |
| Ui | Unifi Dream Machine Beast | all versions listed | Not affected |
| Ui | Unifi Dream Machine Beast Firmware | < 5.1.11 | Affected |
| Ui | Unifi Dream Machine Firmware | < 5.1.12 | Affected |
| Ui | Unifi Dream Machine Pro | all versions listed | Not affected |
| Ui | Unifi Dream Machine Pro Firmware | < 5.1.12 | Affected |
| Ui | Unifi Dream Machine Pro Max | all versions listed | Not affected |
| Ui | Unifi Dream Machine Pro Max Firmware | < 5.1.12 | Affected |
| Ui | Unifi Dream Machine Special Edition | all versions listed | Not affected |
| Ui | Unifi Dream Machine Special Edition Firmware | < 5.1.12 | Affected |
| Ui | Unifi Dream Router | all versions listed | Not affected |
| Ui | Unifi Dream Router 5g Max | all versions listed | Not affected |
| Ui | Unifi Dream Router 5g Max Firmware | < 5.1.12 | Affected |
| Ui | Unifi Dream Router 7 | all versions listed | Not affected |
| Ui | Unifi Dream Router 7 Firmware | < 5.1.12 | Affected |
| Ui | Unifi Dream Router Firmware | < 5.1.12 | Affected |
| Ui | Unifi Dream Wall | all versions listed | Not affected |
| Ui | Unifi Dream Wall Firmware | < 5.1.12 | Affected |
| Ui | Unifi Express 7 | all versions listed | Not affected |
| Ui | Unifi Express 7 Firmware | < 5.1.12 | Affected |
| Ui | Unifi Network Video Recorder | all versions listed | Not affected |
| Ui | Unifi Network Video Recorder Firmware | < 5.1.12 | Affected |
| Ui | Unifi Network Video Recorder G2 | all versions listed | Not affected |
| Ui | Unifi Network Video Recorder G2 Firmware | < 5.1.12 | Affected |
| Ui | Unifi Network Video Recorder G2 Pro | all versions listed | Not affected |
| Ui | Unifi Network Video Recorder G2 Pro Firmware | < 5.1.12 | Affected |
| Ui | Unifi Network Video Recorder Instant | all versions listed | Not affected |
| Ui | Unifi Network Video Recorder Instant Firmware | < 5.1.12 | Affected |
| Ui | Unifi Network Video Recorder Pro | all versions listed | Not affected |
| Ui | Unifi Network Video Recorder Pro Firmware | < 5.1.12 | Affected |
Weakness type
-
CWE-20: Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Attack techniques
Derived through the weakness type: CVE to CWE to CAPEC to ATT&CK. This shows which techniques the weakness class is historically used for. It does not assert that this vulnerability has been exploited that way.
- T1027: Obfuscated Files or Information
- T1036.001: Invalid Code Signature
- T1539: Steal Web Session Cookie
- T1553.002: Code Signing
- T1574.006: Dynamic Linker Hijacking
- T1574.007: Path Interception by PATH Environment Variable
References
- https://community.ui.com/releases/Security-Advisory-Bulletin-064-064/84811c09-4cf4-42ab-b…
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-34910
- https://www.pwndefend.com/2026/06/09/cve-2026-34910-exploitation-itw-building-a-botnet-mi…
Does this affect you?
A vulnerability matters only if you run the product, in an affected version, somewhere an attacker can reach.