CVE-2026-34909 Details
Description
A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to access an underlying account.
A path traversal vulnerability has been identified in UniFi OS devices, allowing malicious actors with network access to access and manipulate files on the underlying system. This could potentially be used to access sensitive account information.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-34909 | CISA-ADP | US Government Resource |
| https://www.pwndefend.com/2026/06/09/cve-2026-34910-exploitation-itw-building-a-botnet-mirai/ | CISA-ADP | ExploitThird Party Advisory |
| https://community.ui.com/releases/Security-Advisory-Bulletin-064-064/84811c09-4cf4-42ab-bd61-cc994445963b | [email protected] | PatchVendor Advisory |
This CVE is in CISA's Known Exploited Vulnerabilities Catalog
Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.
| Vulnerability Name | Date Added | Due Date | Required Action |
|---|---|---|---|
| Ubiquiti UniFi OS Path Traversal Vulnerability | Jun 23, 2026 | Jun 26, 2026 | Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ui unifi os server | < 5.0.8 |
CPE
Remediation
| |
| ui unifi cloud gateway industrial firmware | < 5.1.12 |
CPE
Remediation
| |
| ui unifi cloud gateway industrial | All versions |
CPE
Remediation
| |
| ui unifi dream machine firmware | < 5.1.12 |
CPE
Remediation
| |
| ui unifi dream machine | All versions |
CPE
Remediation
| |
| ui unifi dream machine pro firmware | < 5.1.12 |
CPE
Remediation
| |
| ui unifi dream machine pro | All versions |
CPE
Remediation
| |
| ui unifi dream machine special edition firmware | < 5.1.12 |
CPE
Remediation
| |
| ui unifi dream machine special edition | All versions |
CPE
Remediation
| |
| ui unifi dream machine pro max firmware | < 5.1.12 |
CPE
Remediation
| |
| ui unifi dream machine pro max | All versions |
CPE
Remediation
| |
| ui enterprise fortress gateway firmware | < 5.1.12 |
CPE
Remediation
| |
| ui enterprise fortress gateway | All versions |
CPE
Remediation
| |
| ui unifi dream wall firmware | < 5.1.12 |
CPE
Remediation
| |
| ui unifi dream wall | All versions |
CPE
Remediation
| |
| ui unifi dream router firmware | < 5.1.12 |
CPE
Remediation
| |
| ui unifi dream router | All versions |
CPE
Remediation
| |
| ui unifi dream router 7 firmware | < 5.1.12 |
CPE
Remediation
| |
| ui unifi dream router 7 | All versions |
CPE
Remediation
| |
| ui unifi express 7 firmware | < 5.1.12 |
CPE
Remediation
| |
| ui unifi express 7 | All versions |
CPE
Remediation
| |
| ui unifi network video recorder firmware | < 5.1.12 |
CPE
Remediation
| |
| ui unifi network video recorder | All versions |
CPE
Remediation
| |
| ui unifi network video recorder pro firmware | < 5.1.12 |
CPE
Remediation
| |
| ui unifi network video recorder pro | All versions |
CPE
Remediation
| |
| ui unifi network video recorder instant firmware | < 5.1.12 |
CPE
Remediation
| |
| ui unifi network video recorder instant | All versions |
CPE
Remediation
| |
| ui enterprise network video recorder firmware | < 5.1.12 |
CPE
Remediation
| |
| ui enterprise network video recorder | All versions |
CPE
Remediation
| |
| ui unifi cloud gateway ultra firmware | < 5.1.12 |
CPE
Remediation
| |
| ui unifi cloud gateway ultra | All versions |
CPE
Remediation
| |
| ui unifi cloud gateway max firmware | < 5.1.12 |
CPE
Remediation
| |
| ui unifi cloud gateway max | All versions |
CPE
Remediation
| |
| ui unifi cloud gateway fiber firmware | < 5.1.12 |
CPE
Remediation
| |
| ui unifi cloud gateway fiber | All versions |
CPE
Remediation
| |
| ui unifi dream router 5g max firmware | < 5.1.12 |
CPE
Remediation
| |
| ui unifi dream router 5g max | All versions |
CPE
Remediation
| |
| ui enterprise network video recorder core firmware | < 5.1.12 |
CPE
Remediation
| |
| ui enterprise network video recorder core | All versions |
CPE
Remediation
| |
| ui unifi cloud key plus firmware | < 5.1.12 |
CPE
Remediation
| |
| ui unifi cloud key plus | All versions |
CPE
Remediation
| |
| ui unifi cloudkey firmware | < 5.1.12 |
CPE
Remediation
| |
| ui unifi cloudkey | All versions |
CPE
Remediation
| |
| ui unifi cloudkey enterprise firmware | < 5.1.12 |
CPE
Remediation
| |
| ui unifi cloudkey enterprise | All versions |
CPE
Remediation
| |
| ui unifi network video recorder g2 firmware | < 5.1.12 |
CPE
Remediation
| |
| ui unifi network video recorder g2 | All versions |
CPE
Remediation
| |
| ui unifi network video recorder g2 pro firmware | < 5.1.12 |
CPE
Remediation
| |
| ui unifi network video recorder g2 pro | All versions |
CPE
Remediation
| |
| ui unifi dream machine beast firmware | < 5.1.11 |
CPE
Remediation
| |
| ui unifi dream machine beast | All versions |
CPE
Remediation
| |
| ui unas 2 firmware | < 5.1.10 |
CPE
Remediation
| |
| ui unas 2 | All versions |
CPE
Remediation
| |
| ui unas 4 firmware | < 5.1.10 |
CPE
Remediation
| |
| ui unas 4 | All versions |
CPE
Remediation
| |
| ui unas pro firmware | < 5.1.10 |
CPE
Remediation
| |
| ui unas pro | All versions |
CPE
Remediation
| |
| ui unas pro 4 firmware | < 5.1.10 |
CPE
Remediation
| |
| ui unas pro 4 | All versions |
CPE
Remediation
| |
| ui unas pro 8 firmware | < 5.1.10 |
CPE
Remediation
| |
| ui unas pro 8 | All versions |
CPE
Remediation
| |
| ui unifi express firmware | < 4.0.14 |
CPE
Remediation
| |
| ui unifi express | All versions |
CPE
Remediation
| |
Change History
8 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 23, 2026 | CVE Translated | [email protected] |
| Jun 24, 2026 | Initial Analysis | [email protected] |
| Jun 24, 2026 | CVE Modified | CISA-ADP |
| Jun 23, 2026 | CVE CISA KEV Update | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
| Jun 23, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| May 22, 2026 | New CVE Received | [email protected] |