CRITICAL

CVE-2026-34909

Ui Unifi Os Server 2026-05-22 CVSS v3.1
CVSS
10
KEV

Description

A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to access an underlying account.

Summary dbcve.org

Path traversal vulnerability in UniFi OS allows an attacker with network access to escape intended directories and access sensitive files on the underlying Linux filesystem, potentially exposing credentials or system data.

Mitigation

Apply vendor-provided security patches for UniFi OS devices immediately; restrict network access to management interfaces and implement monitoring for unauthorized file access attempts.

Proof of Concept
Patch Commit

Weakness (CWE)

CWE-22 Path Traversal

EPSS Score

65.04%
Probability of exploitation in next 30 days
99.2th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE