Vulnerability Description
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized changes to the system.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ui | Unifi Os Server | < 5.0.8 |
| Ui | Unifi Cloud Gateway Industrial Firmware | < 5.1.12 |
| Ui | Unifi Cloud Gateway Industrial | - |
| Ui | Unifi Dream Machine Firmware | < 5.1.12 |
| Ui | Unifi Dream Machine | - |
| Ui | Unifi Dream Machine Pro Firmware | < 5.1.12 |
| Ui | Unifi Dream Machine Pro | - |
| Ui | Unifi Dream Machine Special Edition Firmware | < 5.1.12 |
| Ui | Unifi Dream Machine Special Edition | - |
| Ui | Unifi Dream Machine Pro Max Firmware | < 5.1.12 |
| Ui | Unifi Dream Machine Pro Max | - |
| Ui | Enterprise Fortress Gateway Firmware | < 5.1.12 |
| Ui | Enterprise Fortress Gateway | - |
| Ui | Unifi Dream Wall Firmware | < 5.1.12 |
| Ui | Unifi Dream Wall | - |
| Ui | Unifi Dream Router Firmware | < 5.1.12 |
| Ui | Unifi Dream Router | - |
| Ui | Unifi Dream Router 7 Firmware | < 5.1.12 |
| Ui | Unifi Dream Router 7 | - |
| Ui | Unifi Express 7 Firmware | < 5.1.12 |
Related Weaknesses (CWE)
References
- https://community.ui.com/releases/Security-Advisory-Bulletin-064-064/84811c09-4cPatchVendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-US Government Resource
- https://www.pwndefend.com/2026/06/09/cve-2026-34910-exploitation-itw-building-a-ExploitThird Party Advisory
FAQ
What is CVE-2026-34908?
CVE-2026-34908 is a vulnerability with a CVSS score of 10.0 (CRITICAL). A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized changes to the system.
How severe is CVE-2026-34908?
CVE-2026-34908 has been rated CRITICAL with a CVSS base score of 10.0/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-34908?
Check the references section above for vendor advisories and patch information. Affected products include: Ui Unifi Os Server, Ui Unifi Cloud Gateway Industrial Firmware, Ui Unifi Cloud Gateway Industrial, Ui Unifi Dream Machine Firmware, Ui Unifi Dream Machine.