CVE-2026-34910
Overview
This vulnerability is a command injection flaw resulting from improper input validation in UniFi OS Server and related UniFi firmware components. The root cause lies in the failure to sanitize user-supplied input before passing it to system-level command execution functions. Affected components include UniFi OS Server and multiple UniFi device firmware versions, where network-accessible interfaces process untrusted input without adequate validation.
Vulnerability Description
A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.
Impact
An unauthenticated attacker with network access can execute arbitrary system commands on affected UniFi devices, resulting in full system compromise. This enables unauthorized control over device operations, potential data exfiltration, lateral movement within the network, and disruption of network services. The attack requires no user interaction or valid credentials, making it highly exploitable in exposed network environments.
Solution
Ubiquiti has released Security Advisory Bulletin 064 addressing this issue for UniFi OS Server and related firmware. Administrators should apply the latest firmware updates as specified in the advisory available at https://community.ui.com/releases/Security-Advisory-Bulletin-064-064/84811c09-4cf4-42ab-bd61-cc994445963b. The advisory provides detailed patch versions and upgrade instructions for affected UniFi devices to mitigate this vulnerability.
EPSS vs KEV Prediction — Evolution (30 days)
Affected Products (31)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Ui | Unifi Os Server | All |
cpe:2.3:a:ui:unifi_os_server:*:*:*:*:*:*:*:*
|
|
|
Ui | Enterprise Fortress Gateway Firmware | All |
cpe:2.3:o:ui:enterprise_fortress_gateway_firmware:*:*:*:*:*:*:*:*
|
|
|
Ui | Enterprise Network Video Recorder Core Firmware | All |
cpe:2.3:o:ui:enterprise_network_video_recorder_core_firmware:*:*:*:*:*:*:*:*
|
|
|
Ui | Enterprise Network Video Recorder Firmware | All |
cpe:2.3:o:ui:enterprise_network_video_recorder_firmware:*:*:*:*:*:*:*:*
|
|
|
Ui | Unas 2 Firmware | All |
cpe:2.3:o:ui:unas_2_firmware:*:*:*:*:*:*:*:*
|
|
|
Ui | Unas 4 Firmware | All |
cpe:2.3:o:ui:unas_4_firmware:*:*:*:*:*:*:*:*
|
|
|
Ui | Unas Pro 4 Firmware | All |
cpe:2.3:o:ui:unas_pro_4_firmware:*:*:*:*:*:*:*:*
|
|
|
Ui | Unas Pro 8 Firmware | All |
cpe:2.3:o:ui:unas_pro_8_firmware:*:*:*:*:*:*:*:*
|
|
|
Ui | Unas Pro Firmware | All |
cpe:2.3:o:ui:unas_pro_firmware:*:*:*:*:*:*:*:*
|
|
|
Ui | Unifi Cloud Gateway Fiber Firmware | All |
cpe:2.3:o:ui:unifi_cloud_gateway_fiber_firmware:*:*:*:*:*:*:*:*
|
|
|
Ui | Unifi Cloud Gateway Industrial Firmware | All |
cpe:2.3:o:ui:unifi_cloud_gateway_industrial_firmware:*:*:*:*:*:*:*:*
|
|
|
Ui | Unifi Cloud Gateway Max Firmware | All |
cpe:2.3:o:ui:unifi_cloud_gateway_max_firmware:*:*:*:*:*:*:*:*
|
|
|
Ui | Unifi Cloud Gateway Ultra Firmware | All |
cpe:2.3:o:ui:unifi_cloud_gateway_ultra_firmware:*:*:*:*:*:*:*:*
|
|
|
Ui | Unifi Cloud Key Plus Firmware | All |
cpe:2.3:o:ui:unifi_cloud_key_plus_firmware:*:*:*:*:*:*:*:*
|
|
|
Ui | Unifi Cloudkey Enterprise Firmware | All |
cpe:2.3:o:ui:unifi_cloudkey_enterprise_firmware:*:*:*:*:*:*:*:*
|
|
|
Ui | Unifi Cloudkey Firmware | All |
cpe:2.3:o:ui:unifi_cloudkey_firmware:*:*:*:*:*:*:*:*
|
|
|
Ui | Unifi Dream Machine Beast Firmware | All |
cpe:2.3:o:ui:unifi_dream_machine_beast_firmware:*:*:*:*:*:*:*:*
|
|
|
Ui | Unifi Dream Machine Firmware | All |
cpe:2.3:o:ui:unifi_dream_machine_firmware:*:*:*:*:*:*:*:*
|
|
|
Ui | Unifi Dream Machine Pro Firmware | All |
cpe:2.3:o:ui:unifi_dream_machine_pro_firmware:*:*:*:*:*:*:*:*
|
|
|
Ui | Unifi Dream Machine Pro Max Firmware | All |
cpe:2.3:o:ui:unifi_dream_machine_pro_max_firmware:*:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
GitHub PoCs (2)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
Boreas37/CVE-2026-34910-PoC
CVE-2026-34910/34909 — UniFi OS unauth RCE + file read via ..%2f auth bypass (CVSS 10.0, KEV, Mirai ITW)
|
Boreas37 | 14 | 1 | 2026-08-09 | View |
|
gagaltotal/CVE-2026-34910-unifi-poc
CVE-2026-34910 - CVE-2026-34909 Unifi OS
|
gagaltotal | 0 | 0 | 2026-08-22 | View |
Threat Feed
32 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Proof-of-concept code is publicly available for this vulnerability
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Highlighted stages are those attackers typically reach when exploiting this CVE. Heuristic based on CWE families — refined by ML classifier when available.
Attack Vectors ML
MITRE ATT&CK Techniques (0)
Techniques are derived from this CVE's kill chains once ML classification completes.
CAPEC Attack Patterns ML
Red Team Playbook
Executable commands will be auto-mapped to each ATT&CK technique of this CVE.
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (4)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2026-34910 |
| community.ui.com |
GitHub CVE
|
https://community.ui.com/releases/Security-Advisory-Bulletin-064-064/84811c09-4cf4-42ab-bd61-cc994445963b |
| cisa.gov |
NVD API
|
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-34910 |
| pwndefend.com |
NVD API
|
https://www.pwndefend.com/2026/06/09/cve-2026-34910-exploitation-itw-building-a-botnet-mirai/ |