CVE-2026-34909
KEVCRITICAL 10.0EPSS 63.9%
A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to access an underlying account.
- CVSS v3.1
- 10.0 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H - EPSS
- 63.90% chance of exploitation in the next 30 days, 99th percentile
- CISA KEV
- added 2026-06-23
- Published
- 2026-05-22
- Updated
- 2026-06-24
Proof-of-concept exploits (4)
- https://www.pwndefend.com/2026/06/09/cve-2026-34910-exploitation-itw-building-a-botnet-mi…
- Boreas37/CVE-2026-34910-PoC6★ · 2026-08-21
- gagaltotal/CVE-2026-34910-unifi-poc0★ · 2026-08-22
- BoredHackerBlog/unifi_5.0.6_exploitation