CVE-2026-34909
critical · 10Actively exploitedOn the CISA Known Exploited Vulnerabilities catalog
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to access an underlying account.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Weaknesses
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| ui | unifi_os_server | < 5.0.8 |
| ui | unifi_cloud_gateway_industrial_firmware | < 5.1.12 |
| ui | unifi_cloud_gateway_industrial | all versions |
| ui | unifi_dream_machine_firmware | < 5.1.12 |
| ui | unifi_dream_machine | all versions |
| ui | unifi_dream_machine_pro_firmware | < 5.1.12 |
| ui | unifi_dream_machine_pro | all versions |
| ui | unifi_dream_machine_special_edition_firmware | < 5.1.12 |
| ui | unifi_dream_machine_special_edition | all versions |
| ui | unifi_dream_machine_pro_max_firmware | < 5.1.12 |
| ui | unifi_dream_machine_pro_max | all versions |
| ui | enterprise_fortress_gateway_firmware | < 5.1.12 |
| ui | enterprise_fortress_gateway | all versions |
| ui | unifi_dream_wall_firmware | < 5.1.12 |
| ui | unifi_dream_wall | all versions |
| ui | unifi_dream_router_firmware | < 5.1.12 |
| ui | unifi_dream_router | all versions |
| ui | unifi_dream_router_7_firmware | < 5.1.12 |
| ui | unifi_dream_router_7 | all versions |
| ui | unifi_express_7_firmware | < 5.1.12 |
| ui | unifi_express_7 | all versions |
| ui | unifi_network_video_recorder_firmware | < 5.1.12 |
| ui | unifi_network_video_recorder | all versions |
| ui | unifi_network_video_recorder_pro_firmware | < 5.1.12 |
| ui | unifi_network_video_recorder_pro | all versions |
| ui | unifi_network_video_recorder_instant_firmware | < 5.1.12 |
| ui | unifi_network_video_recorder_instant | all versions |
| ui | enterprise_network_video_recorder_firmware | < 5.1.12 |
| ui | enterprise_network_video_recorder | all versions |
| ui | unifi_cloud_gateway_ultra_firmware | < 5.1.12 |
| ui | unifi_cloud_gateway_ultra | all versions |
| ui | unifi_cloud_gateway_max_firmware | < 5.1.12 |
| ui | unifi_cloud_gateway_max | all versions |
| ui | unifi_cloud_gateway_fiber_firmware | < 5.1.12 |
| ui | unifi_cloud_gateway_fiber | all versions |
| ui | unifi_dream_router_5g_max_firmware | < 5.1.12 |
| ui | unifi_dream_router_5g_max | all versions |
| ui | enterprise_network_video_recorder_core_firmware | < 5.1.12 |
| ui | enterprise_network_video_recorder_core | all versions |
| ui | unifi_cloud_key_plus_firmware | < 5.1.12 |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2026-34909