CVE-2026-34908

A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized changes to…

Severity
critical
Actively exploited
actively exploited (KEV)
82.7 %
Critical — model predicts very high exploitation likelihood in the next 30 days.
Published
2026-05-22 00:43 UTC
CWE-284

Weakness classes (CWE)

  • CWE-284Pillar

    Improper Access Control

    The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

    cwe.mitre.org →

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Translated2026-07-23 16:10 UTC· nvd@nist.gov
    • Translation: Title: varios productos de Ubiquiti, Description: Un actor malicioso con acceso a la red podría explotar una vulnerabilidad de control de acceso inadecuado encontrada en dispositivos UniFi OS para realizar cambios no autorizados en el sistema.
  2. Initial Analysis2026-06-24 14:50 UTC· nvd@nist.gov
    • CPE Configuration: OR *cpe:2.3:a:ui:unifi_os_server:*:*:*:*:*:*:*:* versions up to (excluding) 5.0.8
    • CPE Configuration: AND OR *cpe:2.3:o:ui:unifi_cloud_gateway_industrial_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 5.1.12 OR cpe:2.3:h:ui:unifi_cloud_gateway_industrial:-:*:*:*:*:*:*:*
    • CPE Configuration: AND OR *cpe:2.3:o:ui:unifi_dream_machine_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 5.1.12 OR cpe:2.3:h:ui:unifi_dream_machine:-:*:*:*:*:*:*:*
    • CPE Configuration: AND OR *cpe:2.3:o:ui:unifi_dream_machine_pro_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 5.1.12 OR cpe:2.3:h:ui:unifi_dream_machine_pro:-:*:*:*:*:*:*:*
  3. CVE Modified2026-06-24 05:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-34908","role":"CISA Coordinator","options":[{"exploitation":"active"},{"automatable":"yes"},{"technic…{"id":"CVE-2026-34908","role":"CISA Coordinator","options":[{"exploitation":"active"},{"automatable":"yes"},{"technic…
  4. CVE CISA KEV Update2026-06-23 19:00 UTC· 9119a7d8-5eab-497f-8521-727c672e3725
    • Date Added: 2026-06-23
    • Due Date: 2026-06-23
    • Required Action: 2026-06-23
    • Vulnerability Name: 2026-06-23
  5. CVE Modified2026-06-23 18:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • Reference: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-34908
    • Reference: https://www.pwndefend.com/2026/06/09/cve-2026-34910-exploitation-itw-building-a-botnet-mirai/
    • SSVC: {"id":"CVE-2026-34908","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"yes"},{"technical…{"id":"CVE-2026-34908","role":"CISA Coordinator","options":[{"exploitation":"active"},{"automatable":"yes"},{"technic…

Description

A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized changes to the system.

Source: EUVD

Affected operating systems

  • other

    ui / enterprise_fortress_gateway_firmware

  • other

    ui / enterprise_network_video_recorder_core_firmware

  • other

    ui / enterprise_network_video_recorder_firmware

  • other

    ui / unas_2_firmware

  • other

    ui / unas_4_firmware

  • other

    ui / unas_pro_4_firmware

  • other

    ui / unas_pro_8_firmware

  • other

    ui / unas_pro_firmware

  • other

    ui / unifi_cloud_gateway_fiber_firmware

  • other

    ui / unifi_cloud_gateway_industrial_firmware

  • other

    ui / unifi_cloud_gateway_max_firmware

  • other

    ui / unifi_cloud_gateway_ultra_firmware

  • other

    ui / unifi_cloud_key_plus_firmware

  • other

    ui / unifi_cloudkey_enterprise_firmware

  • other

    ui / unifi_cloudkey_firmware

  • other

    ui / unifi_dream_machine_beast_firmware

  • other

    ui / unifi_dream_machine_firmware

  • other

    ui / unifi_dream_machine_pro_firmware

  • other

    ui / unifi_dream_machine_pro_max_firmware

  • other

    ui / unifi_dream_machine_special_edition_firmware

  • other

    ui / unifi_dream_router_5g_max_firmware

  • other

    ui / unifi_dream_router_7_firmware

  • other

    ui / unifi_dream_router_firmware

  • other

    ui / unifi_dream_wall_firmware

Public exploit references

Public proof-of-concepts and detection templates for this vulnerability. Maturity ranges from reported PoCs through working detection scripts up to fully weaponized exploit modules. NEOSEC mirrors the code internally for forensic analysis; externally we only link to the original sources.

References & sources

Linked advisories