Path traversal in Ubiquiti Networks products - CVE-2026-34909
Published: June 26, 2026 / Updated: July 21, 2026
Vulnerability details
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences. A remote attacker can send a specially crafted HTTP request and access files on the underlying system that could be manipulated to access an underlying account.
Affected software
UNVR-G2-Pro
Express 7
UNVR-G2
UNVR
UniFi OS Server
UNVR-Pro
UCK-Enterprise
UNVR-Instant
UDR7
ENVR
UCKP
UCG-Ultra
ENVR-Core
UCG-Max
UDR-5G
UCG-Fiber
UDM-Beast
UDR
UNAS-2
UDW
UNAS-4
EFG
UNAS-Pro
UDM-Pro-Max
UNAS-Pro-4
UDM-SE
UNAS-Pro-8
UDM-Pro
Express
UDM
UCG-Industrial
How to mitigate CVE-2026-34909
UNVR-G2-Pro - update to 5.1.12
Express 7 - update to 5.1.12
UNVR-G2 - update to 5.1.12
UNVR - update to 5.1.12
UniFi OS Server - update to 5.0.8
UNVR-Pro - update to 5.1.12
UCK-Enterprise - update to 5.1.12
UNVR-Instant - update to 5.1.12
UDR7 - update to 5.1.12
ENVR - update to 5.1.12
UCKP - update to 5.1.12
UCG-Ultra - update to 5.1.12
ENVR-Core - update to 5.1.12
UCG-Max - update to 5.1.12
UDR-5G - update to 5.1.12
UCG-Fiber - update to 5.1.12
UDM-Beast - update to 5.1.11
UDR - update to 5.1.12
UNAS-2 - update to 5.1.10
UDW - update to 5.1.12
UNAS-4 - update to 5.1.10
EFG - update to 5.1.12
UNAS-Pro - update to 5.1.10
UDM-Pro-Max - update to 5.1.12
UNAS-Pro-4 - update to 5.1.10
UDM-SE - update to 5.1.12
UNAS-Pro-8 - update to 5.1.10
UDM-Pro - update to 5.1.12
Express - update to 4.0.14
UDM - update to 5.1.12
UCG-Industrial - update to 5.1.12