Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
10.0

CVE-2026-34909: UniFi OS: Malicious network access can access system files

Known exploited
CVE-2026-34909 CVE-2026-34909
Summary

UniFi OS devices have a security weakness that allows an attacker with network access to access sensitive files on the system. This could potentially be used to gain further access to the system. To protect against this, ensure that your UniFi OS devices are up to date with the latest security patches.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
ubiquiti unifi os All versions
ui unifi_os_server < 5.0.8
cpe:2.3:a:ui:unifi_os_server:*:*:*:*:*:*:*:*
ui unifi_cloud_gateway_industrial_firmware < 5.1.12
cpe:2.3:o:ui:unifi_cloud_gateway_industrial_firmware:*:*:*:*:*:*:*:*
ui unifi_dream_machine_firmware < 5.1.12
cpe:2.3:o:ui:unifi_dream_machine_firmware:*:*:*:*:*:*:*:*
ui unifi_dream_machine_pro_firmware < 5.1.12
cpe:2.3:o:ui:unifi_dream_machine_pro_firmware:*:*:*:*:*:*:*:*
ui unifi_dream_machine_special_edition_firmware < 5.1.12
cpe:2.3:o:ui:unifi_dream_machine_special_edition_firmware:*:*:*:*:*:*:*:*
ui unifi_dream_machine_pro_max_firmware < 5.1.12
cpe:2.3:o:ui:unifi_dream_machine_pro_max_firmware:*:*:*:*:*:*:*:*
ui enterprise_fortress_gateway_firmware < 5.1.12
cpe:2.3:o:ui:enterprise_fortress_gateway_firmware:*:*:*:*:*:*:*:*
ui unifi_dream_wall_firmware < 5.1.12
cpe:2.3:o:ui:unifi_dream_wall_firmware:*:*:*:*:*:*:*:*
ui unifi_dream_router_firmware < 5.1.12
cpe:2.3:o:ui:unifi_dream_router_firmware:*:*:*:*:*:*:*:*
ui unifi_dream_router_7_firmware < 5.1.12
cpe:2.3:o:ui:unifi_dream_router_7_firmware:*:*:*:*:*:*:*:*
ui unifi_express_7_firmware < 5.1.12
cpe:2.3:o:ui:unifi_express_7_firmware:*:*:*:*:*:*:*:*
ui unifi_network_video_recorder_firmware < 5.1.12
cpe:2.3:o:ui:unifi_network_video_recorder_firmware:*:*:*:*:*:*:*:*
ui unifi_network_video_recorder_pro_firmware < 5.1.12
cpe:2.3:o:ui:unifi_network_video_recorder_pro_firmware:*:*:*:*:*:*:*:*
ui unifi_network_video_recorder_instant_firmware < 5.1.12
cpe:2.3:o:ui:unifi_network_video_recorder_instant_firmware:*:*:*:*:*:*:*:*
ui enterprise_network_video_recorder_firmware < 5.1.12
cpe:2.3:o:ui:enterprise_network_video_recorder_firmware:*:*:*:*:*:*:*:*
ui unifi_cloud_gateway_ultra_firmware < 5.1.12
cpe:2.3:o:ui:unifi_cloud_gateway_ultra_firmware:*:*:*:*:*:*:*:*
ui unifi_cloud_gateway_max_firmware < 5.1.12
cpe:2.3:o:ui:unifi_cloud_gateway_max_firmware:*:*:*:*:*:*:*:*
ui unifi_cloud_gateway_fiber_firmware < 5.1.12
cpe:2.3:o:ui:unifi_cloud_gateway_fiber_firmware:*:*:*:*:*:*:*:*
ui unifi_dream_router_5g_max_firmware < 5.1.12
cpe:2.3:o:ui:unifi_dream_router_5g_max_firmware:*:*:*:*:*:*:*:*
ui enterprise_network_video_recorder_core_firmware < 5.1.12
cpe:2.3:o:ui:enterprise_network_video_recorder_core_firmware:*:*:*:*:*:*:*:*
ui unifi_cloud_key_plus_firmware < 5.1.12
cpe:2.3:o:ui:unifi_cloud_key_plus_firmware:*:*:*:*:*:*:*:*
ui unifi_cloudkey_firmware < 5.1.12
cpe:2.3:o:ui:unifi_cloudkey_firmware:*:*:*:*:*:*:*:*
ui unifi_cloudkey_enterprise_firmware < 5.1.12
cpe:2.3:o:ui:unifi_cloudkey_enterprise_firmware:*:*:*:*:*:*:*:*
ui unifi_network_video_recorder_g2_firmware < 5.1.12
cpe:2.3:o:ui:unifi_network_video_recorder_g2_firmware:*:*:*:*:*:*:*:*
ui unifi_network_video_recorder_g2_pro_firmware < 5.1.12
cpe:2.3:o:ui:unifi_network_video_recorder_g2_pro_firmware:*:*:*:*:*:*:*:*
ui unifi_dream_machine_beast_firmware < 5.1.11
cpe:2.3:o:ui:unifi_dream_machine_beast_firmware:*:*:*:*:*:*:*:*
ui unas_2_firmware < 5.1.10
cpe:2.3:o:ui:unas_2_firmware:*:*:*:*:*:*:*:*
ui unas_4_firmware < 5.1.10
cpe:2.3:o:ui:unas_4_firmware:*:*:*:*:*:*:*:*
ui unas_pro_firmware < 5.1.10
cpe:2.3:o:ui:unas_pro_firmware:*:*:*:*:*:*:*:*
ui unas_pro_4_firmware < 5.1.10
cpe:2.3:o:ui:unas_pro_4_firmware:*:*:*:*:*:*:*:*
ui unas_pro_8_firmware < 5.1.10
cpe:2.3:o:ui:unas_pro_8_firmware:*:*:*:*:*:*:*:*
ui unifi_express_firmware < 4.0.14
cpe:2.3:o:ui:unifi_express_firmware:*:*:*:*:*:*:*:*
Original title
Ubiquiti UniFi OS Path Traversal Vulnerability
Original description
Ubiquiti UniFi OS contains a path traversal vulnerability which could allow a malicious actor with access to the network to access files on the underlying system that could be manipulated to access an underlying account.
nvd CVSS3.1 10.0
Vulnerability type
CWE-22 Path Traversal
Published: 23 Jun 2026 · Updated: 23 Jul 2026 · First seen: 22 May 2026