Path traversal in Ubiquiti Networks products - CVE-2026-34909

 

Path traversal in Ubiquiti Networks products - CVE-2026-34909

Published: June 26, 2026 / Updated: July 21, 2026


Vulnerability identifier: #VU135471
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-34909
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote attacker to perform directory traversal attacks.

The vulnerability exists due to input validation error when processing directory traversal sequences. A remote attacker can send a specially crafted HTTP request and access files on the underlying system that could be manipulated to access an underlying account.


Affected software

UCK
UNVR-G2-Pro
Express 7
UNVR-G2
UNVR
UniFi OS Server
UNVR-Pro
UCK-Enterprise
UNVR-Instant
UDR7
ENVR
UCKP
UCG-Ultra
ENVR-Core
UCG-Max
UDR-5G
UCG-Fiber
UDM-Beast
UDR
UNAS-2
UDW
UNAS-4
EFG
UNAS-Pro
UDM-Pro-Max
UNAS-Pro-4
UDM-SE
UNAS-Pro-8
UDM-Pro
Express
UDM
UCG-Industrial

How to mitigate CVE-2026-34909

Install updates from vendor's website.

UCK - update to 5.1.12
UNVR-G2-Pro - update to 5.1.12
Express 7 - update to 5.1.12
UNVR-G2 - update to 5.1.12
UNVR - update to 5.1.12
UniFi OS Server - update to 5.0.8
UNVR-Pro - update to 5.1.12
UCK-Enterprise - update to 5.1.12
UNVR-Instant - update to 5.1.12
UDR7 - update to 5.1.12
ENVR - update to 5.1.12
UCKP - update to 5.1.12
UCG-Ultra - update to 5.1.12
ENVR-Core - update to 5.1.12
UCG-Max - update to 5.1.12
UDR-5G - update to 5.1.12
UCG-Fiber - update to 5.1.12
UDM-Beast - update to 5.1.11
UDR - update to 5.1.12
UNAS-2 - update to 5.1.10
UDW - update to 5.1.12
UNAS-4 - update to 5.1.10
EFG - update to 5.1.12
UNAS-Pro - update to 5.1.10
UDM-Pro-Max - update to 5.1.12
UNAS-Pro-4 - update to 5.1.10
UDM-SE - update to 5.1.12
UNAS-Pro-8 - update to 5.1.10
UDM-Pro - update to 5.1.12
Express - update to 4.0.14
UDM - update to 5.1.12
UCG-Industrial - update to 5.1.12

External References

Related Security Bulletins