Ubiquiti UniFi OS — Three Max-Severity Pre-Auth Vulnerabilities (CVE-2026-34908 / 34909 / 34910) in Security Advisory Bulletin 064 — Threadlinqs Intelligence
As of 2026-05-30, Ubiquiti UniFi OS — Three Max-Severity Pre-Auth Vulnerabilities (CVE-2026-34908 / 34909 / 34910) in Security Advisory Bulletin 064 is a critical-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 20 indicators of compromise.
Threat ID: TL-2026-0563 · Severity: CRITICAL · CVSS: 10 · Status: MONITORING · Category: VULNERABILITY
Ubiquiti's Security Advisory Bulletin 064 (2026-05-22) patches five UniFi OS flaws, three of which are CVSS 10.0 and pre-authentication: CVE-2026-34908 (Improper Access Control), CVE-2026-34909 (Path
On 2026-05-22, Ubiquiti published Security Advisory Bulletin 064 addressing five vulnerabilities in UniFi OS, the unified operating system that powers UniFi Cloud Gateways, UniFi Dream Machines, UniFi Express, and the UniFi OS Server (Linux/Windows/macOS) variant. Three of the five flaws — CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910 — carry the maximum CVSS v3.1 base score of 10.0 and are exploitable without authentication over the network. All five were reported through Ubiquiti's HackerOne bug bounty program and were patched in UniFi OS 5.1.12 and UniFi OS Server 5.0.8.
CVE-2026-34908 is an Improper Access Control (CWE-284) defect that permits a remote unauthenticated attacker to make unauthorized changes to the configuration and state of an affected UniFi OS console. Because UniFi OS exposes management surfaces (HTTPS on TCP/443, the UniFi Network UI on TCP/8443, and the UniFi Inform channel on TCP/8080) by default on cloud-gateway products, an attacker who can reach any of these ports can drive privileged state transitions without supplying credentials. The flaw is the foundation of the most severe exploit chain because it allows the unauthenticated caller to invoke functionality previously restricted to administrators — notably the device-management, backup-restore, and update-orchestration endpoints.
CVE-2026-34909 is a Path Traversal (CWE-22) vulnerability that lets the same unauthenticated network attacker step outside the intended file scope and read arbitrary files from the underlying Linux root filesystem. Ubiquiti's own description states the flaw can be manipulated to 'access an underlying account', which in practice means reading the cleartext or hashed credential material the UniFi OS stack stores on disk (administrator account files under /data/unifi-core/config, SQLite databases under /data/unifi/db, and SSH host keys under /etc/ssh). Once an attacker reads these artifacts they can either authenticate to the appliance directly or crack the stored hash offline, transforming a read-only file disclosure into full account takeover.
CVE-2026-34910 is an Improper Input Validation defect (CWE-78 OS Command Injection) reachable after the attacker has 'gained network access' to UniFi OS — meaning the attacker can supply attacker-controlled command fragments to a request handler that ultimately invokes a shell, system(), or popen() with insufficient sanitization. Concatenating CVE-2026-34908 (bypass of the auth gate), CVE-2026-34909 (read of secrets from disk), and CVE-2026-34910 (arbitrary command execution as the unifi service user) yields a complete remote, unauthenticated root-equivalent RCE chain on the appliance. Because UniFi OS runs as root on most cloud-gateway hardware and the unifi-core service has effective sudo privileges, post-exploitation provides device-takeover capability suitable for botnet recruitment, persistent residential/SMB proxy networks, or pivoting into the LAN segment the appliance routes.
CVE-2026-33000 is a second OS command injection that requires authentication and is rated Critical; it is most useful as a privilege-escalation primitive after credentials are obtained, but is also exploitable directly by any legitimate UniFi OS user. CVE-2026-34911 is a high-severity Information Disclosure that leaks system metadata which is useful for fingerprinting affected versions and selecting payloads — the natural reconnaissance partner for the pre-auth chain above.
Exposure data from Censys (cited by BleepingComputer) shows roughly 100,000 UniFi OS management surfaces reachable from the public internet, with approximately half (~50,000 IPs) located in the United States. The remaining endpoints cluster heavily in EU, UK, AU, JP, and BR consumer/SMB networks. Ubiquiti hardware is operationally significant because it sits at the network edge of small businesses, residences, regional ISPs, and remote sites, meaning successful exploitation positions an attacker as a man-in-the-middle for all
Weaknesses (CWE)
CWE-284, CWE-22, CWE-78, CWE-20, CWE-200
Target sectors: small-and-medium-business, managed-service-providers, consumer-residential, education, hospitality, retail, healthcare, regional-isp, remote-site-and-branch-office, government-local-and-state
Target regions: North America, Europe, United Kingdom, Australia, Japan, Brazil, Global
Detections & IOCs
As of 2026-07-27, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 20 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-34908, CVE-2026-34909, CVE-2026-34910, CVE-2026-33000, CVE-2026-34911, T1595, T1592, T1587, T1190, T1133, T1059, T1136, T1098, T1068, T1548