CVE-2026-34910

CRITICAL CISA KEV POC TTE 18d Pub 22/05 Upd 24/06

Overview

This vulnerability is a command injection flaw resulting from improper input validation in UniFi OS Server and related UniFi firmware components. The root cause lies in the failure to sanitize user-supplied input before passing it to system-level command execution functions. Affected components include UniFi OS Server and multiple UniFi device firmware versions, where network-accessible interfaces process untrusted input without adequate validation.

Vulnerability Description

A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.

Impact

An unauthenticated attacker with network access can execute arbitrary system commands on affected UniFi devices, resulting in full system compromise. This enables unauthorized control over device operations, potential data exfiltration, lateral movement within the network, and disruption of network services. The attack requires no user interaction or valid credentials, making it highly exploitable in exposed network environments.

Solution

Ubiquiti has released Security Advisory Bulletin 064 addressing this issue for UniFi OS Server and related firmware. Administrators should apply the latest firmware updates as specified in the advisory available at https://community.ui.com/releases/Security-Advisory-Bulletin-064-064/84811c09-4cf4-42ab-bd61-cc994445963b. The advisory provides detailed patch versions and upgrade instructions for affected UniFi devices to mitigate this vulnerability.

EPSS vs KEV Prediction — Evolution (30 days)

Affected Products (31)

Vendor Product Version CPE
ui Ui Unifi Os Server All cpe:2.3:a:ui:unifi_os_server:*:*:*:*:*:*:*:*
ui Ui Enterprise Fortress Gateway Firmware All cpe:2.3:o:ui:enterprise_fortress_gateway_firmware:*:*:*:*:*:*:*:*
ui Ui Enterprise Network Video Recorder Core Firmware All cpe:2.3:o:ui:enterprise_network_video_recorder_core_firmware:*:*:*:*:*:*:*:*
ui Ui Enterprise Network Video Recorder Firmware All cpe:2.3:o:ui:enterprise_network_video_recorder_firmware:*:*:*:*:*:*:*:*
ui Ui Unas 2 Firmware All cpe:2.3:o:ui:unas_2_firmware:*:*:*:*:*:*:*:*
ui Ui Unas 4 Firmware All cpe:2.3:o:ui:unas_4_firmware:*:*:*:*:*:*:*:*
ui Ui Unas Pro 4 Firmware All cpe:2.3:o:ui:unas_pro_4_firmware:*:*:*:*:*:*:*:*
ui Ui Unas Pro 8 Firmware All cpe:2.3:o:ui:unas_pro_8_firmware:*:*:*:*:*:*:*:*
ui Ui Unas Pro Firmware All cpe:2.3:o:ui:unas_pro_firmware:*:*:*:*:*:*:*:*
ui Ui Unifi Cloud Gateway Fiber Firmware All cpe:2.3:o:ui:unifi_cloud_gateway_fiber_firmware:*:*:*:*:*:*:*:*
ui Ui Unifi Cloud Gateway Industrial Firmware All cpe:2.3:o:ui:unifi_cloud_gateway_industrial_firmware:*:*:*:*:*:*:*:*
ui Ui Unifi Cloud Gateway Max Firmware All cpe:2.3:o:ui:unifi_cloud_gateway_max_firmware:*:*:*:*:*:*:*:*
ui Ui Unifi Cloud Gateway Ultra Firmware All cpe:2.3:o:ui:unifi_cloud_gateway_ultra_firmware:*:*:*:*:*:*:*:*
ui Ui Unifi Cloud Key Plus Firmware All cpe:2.3:o:ui:unifi_cloud_key_plus_firmware:*:*:*:*:*:*:*:*
ui Ui Unifi Cloudkey Enterprise Firmware All cpe:2.3:o:ui:unifi_cloudkey_enterprise_firmware:*:*:*:*:*:*:*:*
ui Ui Unifi Cloudkey Firmware All cpe:2.3:o:ui:unifi_cloudkey_firmware:*:*:*:*:*:*:*:*
ui Ui Unifi Dream Machine Beast Firmware All cpe:2.3:o:ui:unifi_dream_machine_beast_firmware:*:*:*:*:*:*:*:*
ui Ui Unifi Dream Machine Firmware All cpe:2.3:o:ui:unifi_dream_machine_firmware:*:*:*:*:*:*:*:*
ui Ui Unifi Dream Machine Pro Firmware All cpe:2.3:o:ui:unifi_dream_machine_pro_firmware:*:*:*:*:*:*:*:*
ui Ui Unifi Dream Machine Pro Max Firmware All cpe:2.3:o:ui:unifi_dream_machine_pro_max_firmware:*:*:*:*:*:*:*:*
+11 additional CPEs
Warning: The exploits and proof-of-concept (PoC) code listed below are sourced from third-party public repositories. CSURFACE assumes no responsibility for the content, accuracy, or safety of these resources. Use at your own risk. Learn more

GitHub PoCs (2)

Repository Author Stars Forks Date Link
Boreas37/CVE-2026-34910-PoC
CVE-2026-34910/34909 — UniFi OS unauth RCE + file read via ..%2f auth bypass (CVSS 10.0, KEV, Mirai ITW)
Boreas37 14 1 2026-08-09 View
gagaltotal/CVE-2026-34910-unifi-poc
CVE-2026-34910 - CVE-2026-34909 Unifi OS
gagaltotal 0 0 2026-08-22 View
Exploited in Wild CONFIRMED
Ransomware NOT ASSOCIATED
Attacker Interest HIGH
Sightings Few sightings

Threat Feed

32 events
2026-09-16
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-09-09
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-09-08
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-09-04
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-09-01
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-29
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-28
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-27
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-23
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-22
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-18
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-17
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-16
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-15
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-14
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-13
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-12
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-10
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-09
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-09
PoC Published (2 GitHub repositories)

Proof-of-concept code is publicly available for this vulnerability

2026-08-05
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-02
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-20
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-13
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-12
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-10
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-08
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-06
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-02
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-01
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-06-25
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-06-23
Added to CISA KEV Catalog

CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog

Likely Kill Chain

Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.

Applicable Out of scope
Initial Access
TA0001
Execution
TA0002
Persistence
TA0003
Priv. Escalation
TA0004
Defense Evasion
TA0005
Credential Access
TA0006
Lateral Movement
TA0008
Collection
TA0009
Impact
TA0040

Highlighted stages are those attackers typically reach when exploiting this CVE. Heuristic based on CWE families — refined by ML classifier when available.

Attack Vectors ML

OS Command Injection
89% command_injection
Remote Code Execution
80% rce
Improper Input Validation
65% input_validation

MITRE ATT&CK Techniques (0)

ATT&CK techniques pending

Techniques are derived from this CVE's kill chains once ML classification completes.

CAPEC Attack Patterns ML

ID Name ML Conf. Likelihood Severity Link
CAPEC-101 Server Side Include (SSI) Injection
55%
High High
CAPEC-88 OS Command Injection
55%
High High
CAPEC-14 Client-side Injection-induced Buffer Overflow
54%
Medium High
CAPEC-9 Buffer Overflow in Local Command-Line Utilities
52%
High High
CAPEC-22 Exploiting Trust in Client
51%
High High

Red Team Playbook

AtomicRedTeam integration in progress

Executable commands will be auto-mapped to each ATT&CK technique of this CVE.

Detection & Response Rules

No detection or response rules found for this CVE.

No news articles found for this CVE.

References (4)

Title Tags URL
nvd.nist.gov
NVD reference
https://nvd.nist.gov/vuln/detail/CVE-2026-34910
community.ui.com
GitHub CVE
https://community.ui.com/releases/Security-Advisory-Bulletin-064-064/84811c09-4cf4-42ab-bd61-cc994445963b
cisa.gov
NVD API
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-34910
pwndefend.com
NVD API
https://www.pwndefend.com/2026/06/09/cve-2026-34910-exploitation-itw-building-a-botnet-mirai/