CVE-2026-34910
CRITICAL KEV CISA Exploitation: ACTIVE
10.0
CVSS 3.1
Description
A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.
Metadata
Severity & Metrics
10.0
CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
CISA Known Exploited Vulnerability
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA description
Ubiquiti UniFi OS contains an improper input validation vulnerability which could allow a malicious actor with access to the network to conduct command injection.
Affected products (31)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| Ubiquiti Inc | EFG | — | 0 < 5.1.12 |
| Ubiquiti Inc | ENVR | — | 0 < 5.1.12 |
| Ubiquiti Inc | ENVR-Core | — | 0 < 5.1.12 |
| Ubiquiti Inc | Express 7 | — | 0 < 5.1.12 |
| Ubiquiti Inc | UCG-Fiber | — | 0 < 5.1.12 |
| Ubiquiti Inc | UCG-Industrial | — | 0 < 5.1.12 |
| Ubiquiti Inc | UCG-Max | — | 0 < 5.1.12 |
| Ubiquiti Inc | UCG-Ultra | — | 0 < 5.1.12 |
| Ubiquiti Inc | UCK | — | 0 < 5.1.12 |
| Ubiquiti Inc | UCK-Enterprise | — | 0 < 5.1.12 |
| Ubiquiti Inc | UCKP | — | 0 < 5.1.12 |
| Ubiquiti Inc | UDM | — | 0 < 5.1.12 |
| Ubiquiti Inc | UDM-Beast | — | 0 < 5.1.11 |
| Ubiquiti Inc | UDM-Pro | — | 0 < 5.1.12 |
| Ubiquiti Inc | UDM-Pro-Max | — | 0 < 5.1.12 |
| Ubiquiti Inc | UDM-SE | — | 0 < 5.1.12 |
| Ubiquiti Inc | UDR | — | 0 < 5.1.12 |
| Ubiquiti Inc | UDR-5G | — | 0 < 5.1.12 |
| Ubiquiti Inc | UDR7 | — | 0 < 5.1.12 |
| Ubiquiti Inc | UDW | — | 0 < 5.1.12 |
| Ubiquiti Inc | UNAS-2 | — | 0 < 5.1.10 |
| Ubiquiti Inc | UNAS-4 | — | 0 < 5.1.10 |
| Ubiquiti Inc | UNAS-Pro | — | 0 < 5.1.10 |
| Ubiquiti Inc | UNAS-Pro-4 | — | 0 < 5.1.10 |
| Ubiquiti Inc | UNAS-Pro-8 | — | 0 < 5.1.10 |
| Ubiquiti Inc | UniFi OS Server | — | 0 < 5.0.8 |
| Ubiquiti Inc | UNVR | — | 0 < 5.1.12 |
| Ubiquiti Inc | UNVR-G2 | — | 0 < 5.1.12 |
| Ubiquiti Inc | UNVR-G2-Pro | — | 0 < 5.1.12 |
| Ubiquiti Inc | UNVR-Instant | — | 0 < 5.1.12 |
| Ubiquiti Inc | UNVR-Pro | — | 0 < 5.1.12 |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| CWE-20 | cna | CWE-20 Improper Input Validation |
CVSS scores (1)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 10.0 | CRITICAL | 3.1 | cna | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
References (1)