ZeroHour

CVE-2026-34908

KEV PoC mass1

Improper Access Control in Ubiquiti UniFi OS Devices (CVE-2026-34908)

CISA: Ubiquiti UniFi OS Improper Access Control Vulnerability

CVSS 3.1
10.0 critical
EPSS
85%p100
Published
()
KEV added
AI analysis

CVE-2026-34908 is an improper access control flaw (CWE-284) in Ubiquiti UniFi OS, the operating system running on UniFi gateways, Dream Machine appliances, and UniFi network video recorders. An attacker who can reach the device over the network — with no privileges or user interaction required per the CVSS vector — can make unauthorized changes to the system. The CVSS 3.1 score of 10.0 with a changed scope (S:C) indicates a successful attack can compromise the device beyond its intended security boundary, with high impact to confidentiality, integrity, and availability. Any organization running the affected UniFi OS products, including UniFi OS Server and the Dream Machine, Cloud Gateway, Enterprise Fortress, Dream Router, Express, and UNVR lines, is affected; specific vulnerable and fixed firmware versions are not specified in the available data. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2026-06-23, confirming active exploitation, and EPSS assigns an 85.2% probability of exploitation within 30 days (100th percentile); ransomware use is unknown.

What to do: Apply the patched UniFi OS firmware from Ubiquiti's advisory immediately (exact fixed versions are not given in this data) and review affected consoles for unauthorized configuration changes, as the KEV listing requires action under CISA BOD 26-04. Restrict UniFi OS management interfaces and SSH from internet exposure, and isolate or discontinue use of any device that cannot be patched. The same release addresses sibling UniFi OS flaws CVE-2026-34909 and CVE-2026-34910, with CVE-2026-34910 reported exploited in the wild to build a Mirai botnet, so patching covers the full batch.

Affected
Ubiquiti UniFi OS Server
Ubiquiti UniFi Cloud Gateway Industrial firmware
Ubiquiti UniFi Dream Machine firmware
Ubiquiti UniFi Dream Machine Pro firmware
Ubiquiti UniFi Dream Machine Special Edition firmware
Ubiquiti UniFi Dream Machine Pro Max firmware
Ubiquiti UniFi Enterprise Fortress Gateway firmware
Ubiquiti UniFi Dream Wall firmware
Ubiquiti UniFi Dream Router firmware
Ubiquiti UniFi Dream Router 7 firmware
Ubiquiti UniFi Express 7 firmware
Ubiquiti UniFi Network Video Recorder firmware
Estimated exposure
masson the order of 1M+ deployed UniFi OS consoles/gateways, with 100k+ internet-exposed management interfaces — Ubiquiti's UniFi Dream Machine/cloud gateway/UNVR line is one of the most widely deployed SMB and prosumer gateway platforms and public internet-wide scans of UniFi management interfaces consistently show hundreds of thousands of exposed…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized changes to the system.

CISA Known Exploited Vulnerability
Affected
Ubiquiti UniFi OS
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Due date
Ransomware use
Unknown
Vendors
ui
Products
unifi os server, unifi cloud gateway industrial firmware, unifi dream machine firmware, unifi dream machine pro firmware, unifi dream machine special edition firmware, unifi dream machine pro max firmware, enterprise fortress gateway firmware, unifi dream wall firmware, unifi dream router firmware, unifi dream router 7 firmware, unifi express 7 firmware, unifi network video recorder firmware
Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

In the news

CVE-2026-34908: Ubiquiti Networks UniFi OS Server access control ...

CVE-2026-34908, a CVSS 10.0 access-control bypass in Ubiquiti UniFi OS, was added to CISA's KEV catalog amid reported active exploitation.

CISA added CVE-2026-34908 to the Known Exploited Vulnerabilities catalog on June 23, 2026, with remediation due June 26 under BOD 26-04 guidance. The CVSS 10.0 improper access control flaw (CWE-284) in Ubiquiti UniFi OS allows unauthorized system changes without authentication. Multiple news reports referenced by the page describe the max-severity UniFi flaws being exploited in attacks, and an official patch is available.

CVE-2026-34908, CVE-2026-34909, CVE-2026-34910: Ubiquiti UniFi OS ...

Ubiquiti UniFi OS flaws CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910 were added to CISA's KEV, chaining auth bypass into command injection.

Ubiquiti UniFi OS vulnerabilities CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910 were added to CISA's KEV catalog. CVE-2026-34908 (CVSS 10.0, CWE-284) is an unauthenticated improper access control flaw allowing unauthorized system changes, described as the initial entry point. It enables attackers to then leverage chained path traversal and command injection flaws for deeper compromise.

CVE-2026-34908: UniFi OS Auth Bypass Vulnerability

Ubiquiti disclosed CVE-2026-34908, a CVSS 10.0 authentication bypass in UniFi OS letting network-adjacent attackers alter device configuration without credentials.

CVE-2026-34908 is an improper access control flaw (CWE-284) in Ubiquiti UniFi OS devices, disclosed in UI Security Advisory Bulletin 064, with a CVSS 3.1 base score of 10.0. An unauthenticated network-adjacent attacker can bypass access controls and modify system configuration, with scope-changed impact on downstream network services such as routing, VPN, and connected access points. Fixed firmware is available, and workarounds include restricting management ports to trusted subnets, isolating management interfaces on a dedicated VLAN, and disabling remote access features. No public proof-of-concept code was observed at the time of publication.