CVE-2026-34911

HIGH

Ubiquiti INC UniFi OS Server - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Title source: rule
STIX 2.1

Description

A malicious actor with access to the network and low privileges could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to obtain sensitive information.

Scores

CVSS v3 7.7
EPSS 0.0066
EPSS Percentile 46.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (31)
Ubiquiti Inc/EFG < 5.1.12
Ubiquiti Inc/ENVR < 5.1.12
Ubiquiti Inc/ENVR-Core < 5.1.12
Ubiquiti Inc/Express 7 < 5.1.12
Ubiquiti Inc/UCG-Fiber < 5.1.12
Ubiquiti Inc/UCG-Industrial < 5.1.12
Ubiquiti Inc/UCG-Max < 5.1.12
Ubiquiti Inc/UCG-Ultra < 5.1.12
Ubiquiti Inc/UCK < 5.1.12
Ubiquiti Inc/UCK-Enterprise < 5.1.12
... and 21 more
Published May 22, 2026
Tracked Since May 22, 2026