Planned Fix

CVE-2026-34908

Authentication Bypass in Ubiquiti UniFi OS
Loading...

Summary

A malicious actor with access to the network could exploit an improper access control vulnerability in UniFi OS devices to make unauthorized changes to the system. Ubiquiti says the issue affects multiple UniFi OS device families and UniFi OS Server, with fixes released in Security Advisory Bulletin 064. In practice, an attacker could alter device settings and other administrative state without proper authorization.

Why Planned Fix?

4/6
No authentication required
Internal deployment
No user interaction needed
Exploitable in default configuration
No active exploitation or PoC
High impact vulnerability

Exploitation Details

Type
Authentication Bypass
Is exploitable with default configuration?
Yes
Is authentication needed?
No
PoC / Exploit
No
Impact

Make unauthorized changes to device configuration and system state.

Data Manipulation
Exploitation Requirements

None — vulnerable in default configuration

Exploitation Process

An attacker first reaches the UniFi OS management surface from the target network. They then send crafted requests to an administrative action or API path that should enforce authorization but does not. If the flaw is present, the request is accepted without the proper privilege check, allowing the attacker to change settings, users, or other protected device state. Success is confirmed when the device applies unauthorized configuration changes.

Detection Resources
Manual Detection
0
Script Detection
0
Scanner Detection
0

Affected Software

Vendor:Ubiquiti
ProductAffected Versions
UCG-Industrial5.0.13 and earlier
UDM5.0.16 and earlier
UDM-Pro5.0.16 and earlier
UDM-SE5.0.16 and earlier
UDM-Pro-Max5.0.16 and earlier
EFG5.0.16 and earlier
UDW5.0.16 and earlier
UDR5.0.16 and earlier
UDR75.0.16 and earlier
Express 75.0.16 and earlier
UNVR5.0.16 and earlier
UNVR-Pro5.0.16 and earlier
UNVR-Instant5.0.16 and earlier
ENVR5.0.16 and earlier
UCG-Ultra5.0.16 and earlier
UCG-Max5.0.16 and earlier
UCG-Fiber5.0.16 and earlier
UDR-5G5.0.17 and earlier
ENVR-Core5.0.17 and earlier
UCKP5.0.17 and earlier
UCK5.0.17 and earlier
UCK-Enterprise5.0.17 and earlier
UniFi OS Server5.0.6 and earlier
UNVR-G25.1.11 and earlier
UNVR-G2-Pro5.1.11 and earlier
UDM-Beast5.1.8 and earlier
UNAS-25.1.8 and earlier
UNAS-45.1.8 and earlier
UNAS-Pro5.1.8 and earlier
UNAS-Pro-45.1.8 and earlier
UNAS-Pro-85.1.8 and earlier
Description

Operating system and management platform for UniFi consoles and appliances used to administer networking, storage, and video/security services.

Deployment:Typically internal
|
Protocol:HTTPS
|
Ports:443
Affected ComponentNetwork-accessible administrative authorization checks in the UniFi OS management interface.

Network-accessible administrative authorization checks in the UniFi OS management interface.

Enterprise UsageEstimated likelihood that this vendor/product is deployed in enterprise environments. AI-generated estimation based on market presence, product type and adoption signals — not exact data.
Very Low
Low
Medium
High
Very High
Vendor Size:Medium
Vendor Notifications
Remediation
Workaround

Not available

Patch

Not available

Update
Update affected UniFi OS devices to the Security Advisory Bulletin 064 fixed releases: 5.1.12 for most console families, 5.1.10 for UniFi OS Network Attached Storage, 5.1.11 for UDM-Beast, and 5.0.8 for UniFi OS Server.

Update affected UniFi OS devices to the Security Advisory Bulletin 064 fixed releases: 5.1.12 for most console families, 5.1.10 for UniFi OS Network Attached Storage, 5.1.11 for UDM-Beast, and 5.0.8 for UniFi OS Server.

community.ui.com
Threat Intelligence
EPSS data unavailable
CISAKEV
CISA KEV
Not Listed
Active Exploitation
No Evidence
Threat Actors

No known threat actors

Detection Rules

No detection rules available

NVD Data

Published: Loading...Modified: Loading...

Description Summary

A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized changes to the system.

CVSS Base Score

10.0
Critical

CVSS Vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)

Attack Vector (AV)
Physical
Local
Adjacent
Network
Attack Complexity (AC)
High
Low
Privileges Required (PR)
High
Low
None
User Interaction (UI)
Required
None
Scope (S)
Unchanged
Changed
Confidentiality (C)
None
Low
High
Integrity (I)
None
Low
High
Availability (A)
None
Low
High
CWE:CWE-284 Improper Access Control
||
Version From:
|
Version Upto:

Priority History

Planned FixLoading...

Initial analysis