Skip to content
COOEY

EXPOSURES › CVE-2026-34909

CVE-2026-34909

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2026-06-23 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-34909 ↗
⌖ EXPLOITED IN THE WILD SHAME 45/100 exploited-in-wildunpatchedsupply-chaindata-breach

Ubiquiti UniFi OS path traversal vulnerability allows attackers to access and manipulate system files to compromise underlying accounts.

This path traversal flaw in Ubiquiti UniFi OS enables attackers with network access to read and manipulate system files, potentially leading to unauthorized account access. DIB organizations must ensure all Ubiquiti hardware is patched immediately to prevent supply-chain compromise and maintain NIST 800-171 compliance. Failure to patch exposes critical infrastructure to unauthorized data access and potential ransomware entry.

Shame score — A known path traversal vulnerability that allows file access but does not directly enable remote code execution.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Ubiquiti UniFi OS contains a path traversal vulnerability which could allow a malicious actor with access to the network to access files on the underlying system that could be manipulated to access an underlying account.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.