Background
Ubiquiti UniFi OS is the platform that runs on UniFi network appliances — primarily Dream Machines, Dream Routers, and the Cloud Gateway series. These devices are the central controller for UniFi Wi-Fi access points, switches, cameras, and door access hardware. In enterprise and SMB deployments they are gateway and network management devices, making them high-value targets: compromise the UniFi OS controller and you can reach the full network it manages.
Ubiquiti published Security Advisory Bulletin 064 on May 21, 2026, disclosing three vulnerabilities that researchers at Bishop Fox had chained together to achieve unauthenticated root code execution. CISA added all three to the Known Exploited Vulnerabilities catalog on June 23, 2026, with a three-day remediation deadline for federal agencies.
This article covers all three CVEs together because they are individually less significant — the attack chain combining them produces CVSS 10.0 unauthenticated RCE.
Technical Mechanism
CVE-2026-34908 — Improper Access Control (Authentication Bypass)
The root cause is a mismatch between how the application validates authentication on raw request URIs and how the Nginx reverse proxy normalises those URIs before routing.
When a request arrives, the access control check evaluates the raw (un-normalised) request path. Nginx then normalises the path before routing it to the upstream service. A crafted path that bypasses the pattern matching in the access check but normalises to a protected endpoint reaches that endpoint without authentication.
For example, a path like /api/auth/validate-sso/../protected-endpoint might pass the access check for /api/auth/validate-sso/ while Nginx normalises it to /protected-endpoint before forwarding.
CVE-2026-34909 — Path Traversal
A path traversal vulnerability allows access to files on the underlying operating system. Bishop Fox used this in conjunction with CVE-2026-34908 to reach files whose contents are used in the authentication flow, effectively providing the material needed to authenticate to or interact with protected endpoints.
The exact traversal path targets a configuration or credential file on the host. When accessed via the auth-bypass in CVE-2026-34908, it returns file contents without requiring a valid session.
CVE-2026-34910 — Command Injection
A package update endpoint accepts input that is passed to shell commands without sanitisation. This is the actual code execution primitive. The target is the ucs/update/latest_package endpoint, which handles software update requests.
Commands injected via this endpoint execute as a service account with passwordless sudo access to several system binaries. As Bishop Fox noted: “The injected commands execute under a highly privileged service account with passwordless sudo access to several system binaries, making escalation to root trivial.”
The Complete Attack Chain
The chain works as follows:
- CVE-2026-34908: Craft a request URI that bypasses the access control check but routes to the package update endpoint post-normalisation
- CVE-2026-34909: If needed, traverse to a file used in the authentication context to satisfy any token or session requirements at the update endpoint
- CVE-2026-34910: Pass command injection payload in the package update request body — this executes as the privileged service account
- Root escalation: Use the passwordless sudo access available to the service account to escalate to full root
The result is unauthenticated root code execution with no user interaction. Network access to the management interface is the only requirement.
Bishop Fox released a free detection script at GitHub (CVE-2026-34908-check) for testing whether a given instance is vulnerable.
Real-World Exploitation Evidence
CISA added all three CVEs to KEV on June 23, 2026, citing evidence of active exploitation. Ubiquiti devices are consistently targeted due to their broad deployment across enterprise networks, MSP-managed customer environments, and SMB deployments.
The primary observed post-exploitation indicator was the creation of rogue administrator accounts under the username ‘John Sim’ on compromised UniFi OS devices. The consistent username pattern across multiple reported incidents is characteristic of an automated exploitation script in circulation.
Given the quality of the Bishop Fox research disclosure (including proof-of-concept code), public exploit tooling for this chain was available well before KEV addition. The gap between Ubiquiti’s May 21 advisory and KEV addition on June 23 represents approximately 33 days during which the advisory was public but patch adoption was not universal.
Ubiquiti devices are often exposed on the internet — the management interface is accessible from the WAN by default in some configurations, and many deployments don’t restrict management access to trusted IPs.
Impact Assessment
Successful exploitation of this vulnerability chain requires no authentication. Any attacker with network access to the UniFi OS management interface can achieve root code execution:
- Full root code execution — command injection runs in the context of the update process, which executes with root privileges on the underlying Linux system
- Persistence — attackers have added rogue administrator accounts and can install backdoors, cron-based persistence, or modified firmware
- Network-wide visibility — a compromised UniFi OS device sits on the network perimeter; attackers gain visibility into all traffic, VPN credentials, and firewall policy
- Lateral movement — the device manages the wider Ubiquiti estate; compromised controller credentials enable access to access points, switches, and cameras under management
- Credential exposure — path traversal targeting UniFi OS configuration files can expose admin credentials, Wi-Fi PSKs, VPN pre-shared keys, and RADIUS secrets stored on the device
For MSP-managed environments, compromise of a single UniFi OS controller can cascade to all customer sites managed from that controller.
Affected Versions
| Product | Affected Version | Fixed Version |
|---|---|---|
| UniFi Dream Machine Pro | UniFi OS Server < 5.0.8 | 5.0.8 |
| UniFi Dream Machine Special Edition | UniFi OS Server < 5.0.8 | 5.0.8 |
| UniFi Dream Router | UniFi OS Server < 5.0.8 | 5.0.8 |
| UniFi Dream Wall | UniFi OS Server < 5.0.8 | 5.0.8 |
| UniFi Cloud Gateway Max | UniFi OS Server < 5.0.8 | 5.0.8 |
| UniFi Cloud Gateway Ultra | UniFi OS Server < 5.0.8 | 5.0.8 |
The vulnerability does not affect UniFi Network Application running on non-UniFi OS hosts (e.g., self-hosted Debian installs).
Remediation Steps
Update to UniFi OS Server 5.0.8 or later. Updates are available through the UniFi OS management interface under Settings > System > Firmware Update, or by downloading directly from Ubiquiti’s release channel.
The update process is automated and typically completes without full service interruption for network devices managed by the controller.
If immediate update is not possible:
- Restrict management interface access to trusted IP addresses only, using the firewall rules available in UniFi OS Settings > Security
- Disable remote management via
ui.comif it is not required - Place the UniFi OS controller behind a jump host or VPN if WAN-reachable management is operationally required
- Audit for rogue administrator accounts — check UniFi OS > Admins and Users for accounts not created by recognised admins, particularly any named ‘John Sim’ or created at unexpected timestamps
Note that authentication bypass + path traversal + command injection chains in web management interfaces are not mitigable by credential hardening alone. Network-level access restriction is the only effective interim control.
Detection Guidance
Network-based:
- Requests matching
/api/auth/validate-sso/followed by path traversal patterns (../,%2e%2e%2f) in Nginx access logs - Requests to
ucs/update/latest_packagefrom IP addresses that have not completed a standard authentication flow - Unusual outbound connections from the UniFi OS controller IP — the device should not be initiating connections to unknown external hosts
Process/system monitoring (if available):
- Unexpected child processes spawned by
ucs-updateor the package management service - Unexpected sudo invocations from the service account that owns the update endpoint
- New files in
/tmp,/var/tmp, or unexpected cron jobs
Audit logs in UniFi OS:
- Failed and anomalous authentication events in System > Activity in the UniFi OS console
- Unexpected admin account creation or privilege changes
Bishop Fox’s CVE-2026-34908-check detection script is available for rapid assessment of whether exposed instances are running a vulnerable version.
Suricata signature:
alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"Ubiquiti UniFi OS CVE-2026-34908/34909/34910 Exploit Chain Attempt"; flow:established,to_server; http.method; content:"POST"; http.uri; content:"update"; http.request_body; pcre:"/[;&|`$()]/"; classtype:web-application-attack; sid:2034910; rev:1;)
Timeline
| Date | Event |
|---|---|
| April 2026 | Bishop Fox discloses three-CVE chain to Ubiquiti |
| April 2026 | Patches developed and announced alongside disclosure |
| 21 May 2026 | Ubiquiti releases UniFi OS Server 5.0.8 with patches for all three CVEs |
| May–June 2026 | Active exploitation observed; rogue ‘John Sim’ admin accounts created on unpatched devices |
| 23 June 2026 | CISA adds CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910 to KEV catalog |
| 26 June 2026 | CISA BOD 26-04 federal remediation deadline |
References
- Ubiquiti Security Advisory Bulletin 064
- NVD — CVE-2026-34908
- NVD — CVE-2026-34909
- NVD — CVE-2026-34910
- BleepingComputer — Critical UniFi OS bug lets hackers gain root without authentication
- SC Media — Ubiquiti patches three max severity UniFi OS vulnerabilities
- BleepingComputer — CISA warns of max severity Ubiquiti flaws exploited in attacks