S4E just found a high top 10 tcp port service scan
critical·Misconfiguration·Updated Aug 10, 2026

CVE-2026-34908 Scanner

CVE-2026-34908 Scanner - Path Traversal vulnerability in UniFi OS

Est. Time~10 seconds
Scan TypeGroup Scan
Targetsdomain, subdomain, ipv4
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2026-34908
10.0
CVSScritical
Exploitable remotely over the internet · no authentication required.

A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized changes to the system.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
UniFi OS Serverby Ubiquiti Inc
AFFECTED< 5.0.8SAFE ✓≥ 5.0.8
UDMby Ubiquiti Inc
AFFECTED< 5.1.12SAFE ✓≥ 5.1.12
UDM-Proby Ubiquiti Inc
AFFECTED< 5.1.12SAFE ✓≥ 5.1.12
UDM-SEby Ubiquiti Inc
AFFECTED< 5.1.12SAFE ✓≥ 5.1.12
Updated Aug 10, 2026View on NVD →
Detail

UniFi OS is a software platform used by Ubiquiti for managing network devices. It is commonly utilized by enterprises and small businesses for controlling and monitoring network hardware. The software enables users to manage routers, switches, and other networking devices through a centralized interface. Organizations and network administrators rely on UniFi OS for efficient network management and security. The platform is particularly valued for its user-friendly design and comprehensive features that simplify the network administration process. Users of UniFi OS benefit from its ability to streamline network operations and automate various administrative tasks.

The Path Traversal vulnerability in UniFi OS allows an attacker to bypass authentication and access restricted files and directories. This vulnerability exists because of inadequate authorization checks, which permit unauthorized access to system components. As a result, attackers can exploit this weakness to execute unauthorized system changes. The exposure can lead to significant security threats, as it may allow attackers to compromise device integrity. This vulnerability is particularly critical because it affects the core functionality related to system authorization and access control.

The vulnerability allows potential attackers to bypass standard authentication processes by manipulating URL paths using traversal sequences. Specifically, the use of "..%2f" in the URL path can exploit the system's inability to properly check for authorization, making certain system files accessible. Furthermore, the specific vulnerable endpoint is located at '/api/auth/validate-sso/..%2f..%2f..%2fproxy/users/api/v2/ucs/update/latest_package'. The vulnerable parameter in the URL path leads to unauthorized access, potentially introducing security threats. The attack can be initiated remotely by any network attacker, increasing its severity significantly.

When exploited, this Path Traversal vulnerability can result in unauthorized system modifications and compromise the security of the device. Attackers could gain access to sensitive information, control on device settings, or even insert malicious software. The exploitation could ultimately lead to loss of data integrity, confidentiality breaches, and system availability issues. Organizations might suffer from service disruptions and may encounter reputational damage if their systems are compromised. Remediating such exploits requires urgent attention to prevent further security breaches and unauthorized access.

REFERENCES

Solution Advice
  • Update to the latest version of UniFi OS to mitigate the Path Traversal vulnerability.
  • Regularly monitor and review system access logs to detect unauthorized access attempts.
  • Consider implementing additional network security controls like firewalls and intrusion detection/prevention systems.
  • Conduct routine vulnerability assessments to identify and address potential security flaws promptly.
  • Ensure proper security configuration management across the network devices using UniFi OS.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.