VULNERABILITY OVERVIEW
Three CVSS 10.0 vulnerabilities (CVE-2026-34908 improper access control, CVE-2026-34909 path traversal, CVE-2026-34910 command injection) chain into a fully unauthenticated root takeover of any UniFi OS device. Bishop Fox confirmed the NGINX authentication gateway bypass and demonstrated command injection against a live 5.0.6 target; Censys tracks nearly 100,000 internet-exposed UniFi OS endpoints. Wild exploitation was confirmed — attackers created rogue 'John Sim' administrator accounts during automated reconnaissance — and CISA added all three to KEV on June 23, 2026.
CVSS BREAKDOWN
↗
Attack Vector
NETWORK
△
Attack Complexity
LOW
⚷
Privs Required
NONE
◈
User Interaction
NONE
⊕
Scope / Impact
CHANGED
C:H · I:H · A:H
AFFECTED VERSIONS
UniFi OS Server <= 5.0.6; firmware < 5.1.12 (UDM/UDR/UNVR series); UniFi Express < 4.0.14; UNAS < 5.1.10CITATIONS
- → https://community.ui.com/releases/Security-Advisory-Bulletin-064-064/84811c09-4cf4-42ab-bd61-cc994445963b
- → https://www.securityweek.com/critical-ubiquiti-vulnerabilities-in-attackers-crosshairs/
- → https://www.cisa.gov/news-events/alerts/2026/06/23/cisa-adds-four-known-exploited-vulnerabilities-catalog
- → https://threataft.com/articles/ubiquiti-unifi-os-cve-2026-34908-34909-34910-rce