CVE-2026-34909

Confirmed PUBLISHED

A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the...

Ubiquiti Inc · UniFi OS Server, Express, UDM, UDM-Pro, UDM-SE, UDM-Pro-Max, UDM-Beast, EFG, UDW, UDR, UDR7, UDR-5G, Express 7, UNVR, UNVR-Pro, UNVR-Instant, UNVR-G2, UNVR-G2-Pro, ENVR, ENVR-Core, UNAS-2, UNAS-4, UNAS-Pro, UNAS-Pro-4, UNAS-Pro-8, UCKP, UCK, UCK-Enterprise, UCG-Ultra, UCG-Max, UCG-Fiber, UCG-Industrial

14 days faster than CISA KEV

Exploited in the wild

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
10.0 Critical EPSS 2.3%

At a Glance

A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to access an underlying account.

cisa
CVE Published
May 22, 2026
Exploitation Reported
Jun 09, 2026
CVSS
10.0 Critical
EPSS
2.3%
Remote Low complexity No user interaction Unauthenticated

Affected Versions

32 version rows · page 2 of 2

Vendor Product Version Status
Ubiquiti Inc
UCKP

0 to < 5.1.12

Affected
Ubiquiti Inc
UCK

0 to < 5.1.12

Affected
Ubiquiti Inc
UCK-Enterprise

0 to < 5.1.12

Affected
Ubiquiti Inc
UCG-Ultra

0 to < 5.1.12

Affected
Ubiquiti Inc
UCG-Max

0 to < 5.1.12

Affected
Ubiquiti Inc
UCG-Fiber

0 to < 5.1.12

Affected
Ubiquiti Inc
UCG-Industrial

0 to < 5.1.12

Affected

CVE References

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.