CVE-2026-34909

CRITICAL

Ubiquiti INC UniFi OS Server - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Title source: rule
STIX 2.1

Description

A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to access an underlying account.

Scores

CVSS v3 10.0
EPSS 0.0062
EPSS Percentile 44.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-22
Status published
Products (32)
Ubiquiti Inc/EFG < 5.1.12
Ubiquiti Inc/ENVR < 5.1.12
Ubiquiti Inc/ENVR-Core < 5.1.12
Ubiquiti Inc/Express < 4.0.14
Ubiquiti Inc/Express 7 < 5.1.12
Ubiquiti Inc/UCG-Fiber < 5.1.12
Ubiquiti Inc/UCG-Industrial < 5.1.12
Ubiquiti Inc/UCG-Max < 5.1.12
Ubiquiti Inc/UCG-Ultra < 5.1.12
Ubiquiti Inc/UCK < 5.1.12
... and 22 more
Published May 22, 2026
Tracked Since May 22, 2026