CRITICAL

CVE-2026-34910

Ui Unifi Os Server 2026-05-22 CVSS v3.1
CVSS
10
KEV

Description

A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.

Summary dbcve.org

This is an improper input validation vulnerability in UniFi OS devices that allows remote command injection. An attacker with network access can exploit unsanitized input fields to inject and execute arbitrary OS commands on the affected device, potentially compromising the entire network infrastructure managed by the device.

Mitigation

Apply vendor-supplied patches from Ubiquiti for UniFi OS devices immediately upon release. In the interim, restrict network access to management interfaces and implement network segmentation to limit exposure.

Proof of Concept
Patch Commit

Weakness (CWE)

CWE-20 Improper Input Validation

EPSS Score

87.47%
Probability of exploitation in next 30 days
99.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE