CRITICAL🚩 CISA KEV⚡ EXPLOIT✓ PATCH🇵🇱 Wersja polska

CVE-2026-34909

CVSS 10.0v3.1pub. 2026-05-22upd. 2026-06-24

A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to access an underlying account.

🤖 AI Analysis
How it works

An attacker with access to the network where the UniFi OS device is operating can send a specially crafted request containing path traversal sequences (e.g., '../'). This allows escaping the allowed directory and reading arbitrary files at the operating system level. The read files may contain authentication or configuration data, whose manipulation enables system account takeover.

Impact

An attacker can gain unauthorized access to sensitive system files and take control of an account in the device's operating system, potentially leading to complete device takeover.

Mitigation & patch

Security patches available from the manufacturer should be applied according to the references: https://community.ui.com/releases/Security-Advisory-Bulletin-064-064/84811c09-4cf4-42ab-bd61-cc994445963b

Who is affected

Devices running UniFi OS — specific versions indicated in the manufacturer's references (Security Advisory Bulletin 064).

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
  • Ui Enterprise Fortress Gateway

    HW
    Ui
    all versions
  • Ui Enterprise Fortress Gateway Firmware

    OS
    Ui
    < 5.1.12
  • Ui Enterprise Network Video Recorder

    HW
    Ui
    all versions
  • Ui Enterprise Network Video Recorder Core

    HW
    Ui
    all versions
  • Ui Enterprise Network Video Recorder Core Firmware

    OS
    Ui
    < 5.1.12
  • Ui Enterprise Network Video Recorder Firmware

    OS
    Ui
    < 5.1.12
  • Ui Unas 2

    HW
    Ui
    all versions
  • Ui Unas 2 Firmware

    OS
    Ui
    < 5.1.10
  • Ui Unas 4

    HW
    Ui
    all versions
  • Ui Unas 4 Firmware

    OS
    Ui
    < 5.1.10
  • Ui Unas Pro

    HW
    Ui
    all versions
  • Ui Unas Pro 4

    HW
    Ui
    all versions
  • Ui Unas Pro 4 Firmware

    OS
    Ui
    < 5.1.10
  • Ui Unas Pro 8

    HW
    Ui
    all versions
  • Ui Unas Pro 8 Firmware

    OS
    Ui
    < 5.1.10
  • Ui Unas Pro Firmware

    OS
    Ui
    < 5.1.10
  • Ui Unifi Cloud Gateway Fiber

    HW
    Ui
    all versions
  • Ui Unifi Cloud Gateway Fiber Firmware

    OS
    Ui
    < 5.1.12
  • Ui Unifi Cloud Gateway Industrial

    HW
    Ui
    all versions
  • Ui Unifi Cloud Gateway Industrial Firmware

    OS
    Ui
    < 5.1.12
  • Ui Unifi Cloud Gateway Max

    HW
    Ui
    all versions
  • Ui Unifi Cloud Gateway Max Firmware

    OS
    Ui
    < 5.1.12
  • Ui Unifi Cloud Gateway Ultra

    HW
    Ui
    all versions
  • Ui Unifi Cloud Gateway Ultra Firmware

    OS
    Ui
    < 5.1.12
  • Ui Unifi Cloudkey

    HW
    Ui
    all versions
  • Ui Unifi Cloudkey Enterprise

    HW
    Ui
    all versions
  • Ui Unifi Cloudkey Enterprise Firmware

    OS
    Ui
    < 5.1.12
  • Ui Unifi Cloudkey Firmware

    OS
    Ui
    < 5.1.12
  • Ui Unifi Cloud Key Plus

    HW
    Ui
    all versions
  • Ui Unifi Cloud Key Plus Firmware

    OS
    Ui
    < 5.1.12

CISA KEV — detailsi

Vendori
Ubiquiti
Producti
UniFi OS
Added to KEVi
June 23, 2026
Remediation deadline (US Federal)i
June 26, 2026(overdue)
Required action (CISA)i

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CISA descriptioni

Ubiquiti UniFi OS contains a path traversal vulnerability which could allow a malicious actor with access to the network to access files on the underlying system that could be manipulated to access an underlying account.

🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
CISA DEADLINE: 26 czerwca 2026
Tags
Path Traversal
CWE
References

Related vulnerabilities

CVE-2026-34910CRITICAL10.0⚠ KEVPL ✓same product

Command Injection w UniFi OS via nieprawidłowa walidacja wejścia

CVE-2026-34908CRITICAL10.0⚠ KEVPL ✓same product

Nieprawidłowa kontrola dostępu w UniFi OS — nieautoryzowane zmiany systemowe

CVE-2026-54402CRITICAL9.9PL ✓same product

Command Injection w UniFi OS przez błąd walidacji wejścia

CVE-2026-33000CRITICAL9.1PL ✓same product

Command Injection w UniFi OS — podatność na wstrzyknięcie poleceń

CVE-2023-24104CRITICAL9.8PL ✓same product

Ubiquiti UniFi Dream Machine Pro — obejście restrykcji domenowych