CVE-2026-34908
KEVCRITICAL 10.0EPSS 85.2%
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized changes to the system.
- CVSS v3.1
- 10.0 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H - EPSS
- 85.19% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2026-06-23
- Nuclei
- critical · CWE-284
- Published
- 2026-05-22
- Updated
- 2026-06-24
Proof-of-concept exploits (3)
- https://www.pwndefend.com/2026/06/09/cve-2026-34910-exploitation-itw-building-a-botnet-mi…
- Boreas37/CVE-2026-34910-PoC6★ · 2026-08-21
- BoredHackerBlog/unifi_5.0.6_exploitation