CRITICAL
CVE-2026-34908
CVSS
10
KEV
Description
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized changes to the system.
Summary dbcve.org
Improper Access Control vulnerability in UniFi OS devices allows a malicious actor with network access to make unauthorized changes to the system. The CVSS 10 score indicates critical severity with complete system compromise potential.
Mitigation
Apply available UniFi OS firmware updates; restrict network access to trusted personnel and implement network segmentation to limit exposure.
Weakness (CWE)
CWE-284
Improper Access Control
EPSS Score
85.19%
Probability of exploitation in next 30 days
99.7th percentile
References
https://community.ui.com/releases/Security-Advisory-Bulletin-064-064/84811c09-4cf4-42ab-bd61-cc994445963b
Patch, Vendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-34908
US Government Resource
https://www.pwndefend.com/2026/06/09/cve-2026-34910-exploitation-itw-building-a-botnet-mirai/
Exploit, Third Party Advisory
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.