CRITICAL

CVE-2026-34908

Ui Unifi Os Server 2026-05-22 CVSS v3.1
CVSS
10
KEV

Description

A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized changes to the system.

Summary dbcve.org

Improper Access Control vulnerability in UniFi OS devices allows a malicious actor with network access to make unauthorized changes to the system. The CVSS 10 score indicates critical severity with complete system compromise potential.

Mitigation

Apply available UniFi OS firmware updates; restrict network access to trusted personnel and implement network segmentation to limit exposure.

Proof of Concept
Patch Commit

Weakness (CWE)

CWE-284 Improper Access Control

EPSS Score

85.19%
Probability of exploitation in next 30 days
99.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE