UniFi OS Server - Command Injection
CVE-2026-34910
Verified
Description
A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.
Severity
Critical
CVSS Score
10
Exploit Probability
46%
Published Date
June 9, 2026
Template Author
kazgangap
CVE-2026-34910.yaml
10.0Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVE ID:
cve-2026-34910
References
https://bishopfox.com/blog/popping-root-on-unifi-os-server-unauthenticated-rce-chain-detection-analysishttps://nvd.nist.gov/vuln/detail/CVE-2026-34910https://community.ui.com/releases/Security-Advisory-Bulletin-064-064/84811c09-4cf4-42ab-bd61-cc994445963bhttps://www.it-connect.tech/critical-3-exploit-chain-grants-root-access-on-unifi-os-server/
Remediation Steps
Update to the latest version of UniFi OS.