← Back to CVE List
Vulnerability Intelligence Report
Ubiquiti UniFi OS Path Traversal Vulnerability

CVE-2026-34909

A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to access an underlying account.

CISA KEV SSVC: Active Exploitation Automatable
CVSS Base Score
10.0
CRITICAL
Exploitability:3.9
Impact Score:6.1
EPSS Probability:1.82%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-22 ↗CWE-22 Path Traversal

Affected Products & Versions

Vendor Product Affected Versions
Ubiquiti Inc UniFi OS Server 0 < 5.0.8 (affected)
Ubiquiti Inc Express 0 < 4.0.14 (affected)
Ubiquiti Inc UDM 0 < 5.1.12 (affected)
Ubiquiti Inc UDM-Pro 0 < 5.1.12 (affected)
Ubiquiti Inc UDM-SE 0 < 5.1.12 (affected)
Ubiquiti Inc UDM-Pro-Max 0 < 5.1.12 (affected)
Ubiquiti Inc UDM-Beast 0 < 5.1.11 (affected)
Ubiquiti Inc EFG 0 < 5.1.12 (affected)
Ubiquiti Inc UDW 0 < 5.1.12 (affected)
Ubiquiti Inc UDR 0 < 5.1.12 (affected)
Ubiquiti Inc UDR7 0 < 5.1.12 (affected)
Ubiquiti Inc UDR-5G 0 < 5.1.12 (affected)
Ubiquiti Inc Express 7 0 < 5.1.12 (affected)
Ubiquiti Inc UNVR 0 < 5.1.12 (affected)
Ubiquiti Inc UNVR-Pro 0 < 5.1.12 (affected)
Ubiquiti Inc UNVR-Instant 0 < 5.1.12 (affected)
Ubiquiti Inc UNVR-G2 0 < 5.1.12 (affected)
Ubiquiti Inc UNVR-G2-Pro 0 < 5.1.12 (affected)
Ubiquiti Inc ENVR 0 < 5.1.12 (affected)
Ubiquiti Inc ENVR-Core 0 < 5.1.12 (affected)
Ubiquiti Inc UNAS-2 0 < 5.1.10 (affected)
Ubiquiti Inc UNAS-4 0 < 5.1.10 (affected)
Ubiquiti Inc UNAS-Pro 0 < 5.1.10 (affected)
Ubiquiti Inc UNAS-Pro-4 0 < 5.1.10 (affected)
Ubiquiti Inc UNAS-Pro-8 0 < 5.1.10 (affected)
Ubiquiti Inc UCKP 0 < 5.1.12 (affected)
Ubiquiti Inc UCK 0 < 5.1.12 (affected)
Ubiquiti Inc UCK-Enterprise 0 < 5.1.12 (affected)
Ubiquiti Inc UCG-Ultra 0 < 5.1.12 (affected)
Ubiquiti Inc UCG-Max 0 < 5.1.12 (affected)
Ubiquiti Inc UCG-Fiber 0 < 5.1.12 (affected)
Ubiquiti Inc UCG-Industrial 0 < 5.1.12 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
EPSS Score
1.825%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityHackerOne · Bug Bounty Provider · USA
Reserved2026-03-31T15:00:06
Published2026-05-22T00:43:49
Last Updated2026-06-24T03:56:19

LINK COPIED TO CLIPBOARD