CVE-2026-34909
A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to access an u...
Affects 0 products across 1 vendor.
Attacker manipulates file path inputs to access files outside the intended directory.
Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.
A critical Path Traversal vulnerability in UniFi OS devices allows network-accessible attackers to access and manipulate files on the underlying system, potentially gaining unauthorized access to accounts.
BSID: BS-2026-GLOBAL-187983-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2026-34909?
What is the CVSS score for CVE-2026-34909?
Is CVE-2026-34909 actively exploited?
How do I remediate CVE-2026-34909?
What systems are affected by CVE-2026-34909?
| CVE ID | CVE-2026-34909 |
|---|---|
| BSID | BS-2026-GLOBAL-187983-C BreachSpider Global ID |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| Published | 2026-05-22 |
| Last Modified | 2026-06-23 |
| ICS Relevance | 15% |
| Weakness (CWE) | |
| Source | NVD |
A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to access an underlying account.
Source: NIST NVD / MITRE CVE Database
The vulnerability is exploited by sending specially crafted requests to the UniFi OS device, which can traverse the file system to access sensitive files.
Exploitation Likelihood: CRITICAL
| Vendor | Product | Fixed Version |
|---|---|---|
| Files | — | — |
No patch URL on record. Monitor vendor security advisories directly.
| CISA KEV | ● Active Exploitation Confirmed (added 2026-06-23) |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
SAGE Enrichment Record — provenance & audit hash
| Model | /workspace/models/qwen2.5-coder-32b-instruct-bf16 |
|---|---|
| Confidence | HIGH |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | 26e861270a8aa59f86471a8468fd60d0af731a9e7be418dacc13e0c0072ab3b1350a720e5db17256f4bfe575a5c6f78be9e4913fc8bd6de28418a42c14e477d7 |
This Vulnerability Is Being Actively Exploited
CVE-2026-34909 is on the CISA KEV list - confirmed active exploitation in the wild. BreachSpider alerts your team within 15 minutes when KEV vulnerabilities match your ICS assets.
Start Free KEV Monitoring →