Planned Fix

CVE-2026-34909

Path Traversal in Ubiquiti UniFi OS
Loading...

Summary

A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to access an underlying account. The flaw appears to be unauthenticated and requires no user interaction, affecting multiple UniFi OS appliance families.

Why Planned Fix?

4/6
No authentication required
Internal deployment
No user interaction needed
Exploitable in default configuration
No active exploitation or PoC
High impact vulnerability

Exploitation Details

Type
Path Traversal
Is exploitable with default configuration?
Yes
Is authentication needed?
No
PoC / Exploit
No
Impact

Read and modify files on the underlying system to access an underlying account.

Privilege Escalation
Exploitation Requirements

None — vulnerable in default configuration

Exploitation Process

An attacker sends crafted requests to the UniFi OS management interface containing traversal sequences such as ../ or encoded variants to escape the intended file scope. If the request reaches the vulnerable file-handling path, the attacker can read or alter files outside the expected directory and may use that access to reach an underlying account.

Detection Resources
Manual Detection
0
Script Detection
0
Scanner Detection
0

Affected Software

Vendor:Ubiquiti
ProductAffected Versions
UCG-Industrial5.0.13 and earlier
UDM5.0.16 and earlier
UDM-Pro5.0.16 and earlier
UDM-SE5.0.16 and earlier
UDM-Pro-Max5.0.16 and earlier
EFG5.0.16 and earlier
UDW5.0.16 and earlier
UDR5.0.16 and earlier
UDR75.0.16 and earlier
Express 75.0.16 and earlier
UNVR5.0.16 and earlier
UNVR-Pro5.0.16 and earlier
UNVR-Instant5.0.16 and earlier
ENVR5.0.16 and earlier
UCG-Ultra5.0.16 and earlier
UCG-Max5.0.16 and earlier
UCG-Fiber5.0.16 and earlier
UDR-5G5.0.17 and earlier
ENVR-Core5.0.17 and earlier
UCKP5.0.17 and earlier
UCK5.0.17 and earlier
UCK-Enterprise5.0.17 and earlier
UniFi OS Server5.0.6 and earlier
UNVR-G25.1.11 and earlier
UNVR-G2-Pro5.1.11 and earlier
UDM-Beast5.1.8 and earlier
UNAS-25.1.8 and earlier
UNAS-45.1.8 and earlier
UNAS-Pro5.1.8 and earlier
UNAS-Pro-45.1.8 and earlier
UNAS-Pro-85.1.8 and earlier
Description

Operating system that powers Ubiquiti UniFi network appliances such as gateways, consoles, network video recorders, and storage devices.

Deployment:Typically internal
|
Protocol:HTTPS
|
Ports:443
Affected ComponentFile path handling in the UniFi OS web management interface.

File path handling in the UniFi OS web management interface.

Enterprise UsageEstimated likelihood that this vendor/product is deployed in enterprise environments. AI-generated estimation based on market presence, product type and adoption signals — not exact data.
Very Low
Low
Medium
High
Very High
Vendor Size:Medium
Remediation
Workaround

Not available

Patch

Not available

Update
Upgrade affected UniFi OS devices to the fixed releases in Security Advisory Bulletin 064: 5.1.12 or later for most gateway/controller families, 5.0.8 or later for UniFi OS Server, 5.1.10 or later for UNAS devices, and 5.1.11 or later for UDM-Beast.

Upgrade affected UniFi OS devices to the fixed releases in Security Advisory Bulletin 064: 5.1.12 or later for most gateway/controller families, 5.0.8 or later for UniFi OS Server, 5.1.10 or later for UNAS devices, and 5.1.11 or later for UDM-Beast.

community.ui.com
Threat Intelligence
EPSS data unavailable
CISAKEV
CISA KEV
Not Listed
Active Exploitation
No Evidence
Threat Actors

No known threat actors

Detection Rules

No detection rules available

NVD Data

Published: Loading...Modified: Loading...

Description Summary

A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to access an underlying account.

CVSS Base Score

10.0
Critical

CVSS Vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)

Attack Vector (AV)
Physical
Local
Adjacent
Network
Attack Complexity (AC)
High
Low
Privileges Required (PR)
High
Low
None
User Interaction (UI)
Required
None
Scope (S)
Unchanged
Changed
Confidentiality (C)
None
Low
High
Integrity (I)
None
Low
High
Availability (A)
None
Low
High
CWE:CWE-22 Path Traversal
||
Version From:
|
Version Upto:

Sources

1
SourceArticle
community.ui.comSecurity Advisory Bulletin 064

Priority History

Planned FixLoading...

Initial analysis