/Vulnerability Library

UniFi OS Server - Command Injection

CVE-2026-34910
Verified

Description

A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.

Severity

Critical

CVSS Score

10

Exploit Probability

46%

Published Date

June 9, 2026

Template Author

kazgangap

CVE-2026-34910.yaml
10.0Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVE ID:
cve-2026-34910

References

https://bishopfox.com/blog/popping-root-on-unifi-os-server-unauthenticated-rce-chain-detection-analysishttps://nvd.nist.gov/vuln/detail/CVE-2026-34910https://community.ui.com/releases/Security-Advisory-Bulletin-064-064/84811c09-4cf4-42ab-bd61-cc994445963bhttps://www.it-connect.tech/critical-3-exploit-chain-grants-root-access-on-unifi-os-server/

Remediation Steps

Update to the latest version of UniFi OS.