CVE-2026-34909

● KEV CRITICAL

A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to access an u...

Affects 0 products across 1 vendor.

BCS6.14
CVSS 3.110.0
EPSS62.8%
Percentile99th
PatchUnknown
KEV Added2026-06-23
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, can impact systems beyond the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-22: Path Traversal

Attacker manipulates file path inputs to access files outside the intended directory.

Related Attack Patterns (CAPEC)
CAPEC-64 Using Slashes and URL Encoding Combined to Bypass Validation Logic
via CWE-22
CAPEC-76 Manipulating Web Input to File System Calls
via CWE-22
CAPEC-78 Using Escaped Slashes in Alternate Encoding
via CWE-22
CAPEC-79 Using Slashes in Alternate Encoding
via CWE-22
CAPEC-126 Path Traversal
via CWE-22

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

A critical Path Traversal vulnerability in UniFi OS devices allows network-accessible attackers to access and manipulate files on the underlying system, potentially gaining unauthorized access to accounts.

BSID: BS-2026-GLOBAL-187983-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2026-34909?
A critical Path Traversal vulnerability in UniFi OS devices allows network-accessible attackers to access and manipulate files on the underlying system, potentially gaining unauthorized access to accounts.
What is the CVSS score for CVE-2026-34909?
CVE-2026-34909 has CVSS 10.0 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. EPSS: 62.8%.
Is CVE-2026-34909 actively exploited?
Yes. CVE-2026-34909 is in the CISA KEV catalog (added 2026-06-23). Active exploitation confirmed. Immediate patching required.
How do I remediate CVE-2026-34909?
Priority: IMMEDIATE.
What systems are affected by CVE-2026-34909?
CVE-2026-34909 affects: Files.
Vulnerability Details
CVE IDCVE-2026-34909
BSIDBS-2026-GLOBAL-187983-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Published2026-05-22
Last Modified2026-06-23
ICS Relevance15%
Weakness (CWE)
SourceNVD
Official Description

A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to access an underlying account.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability is exploited by sending specially crafted requests to the UniFi OS device, which can traverse the file system to access sensitive files.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductFixed Version
Files —
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 76 Days
CISA KEV● Active Exploitation Confirmed (added 2026-06-23)
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hash26e861270a8aa59f86471a8468fd60d0af731a9e7be418dacc13e0c0072ab3b1350a720e5db17256f4bfe575a5c6f78be9e4913fc8bd6de28418a42c14e477d7
Related CVEs affecting Files
CVE-1999-0498 10.0 TFTP is not running in a restricted directory, allowing a remote attacker to ... CVE-1999-0561 10.0 IIS has the #exec function enabled for Server Side Include (SSI) files. CVE-1999-0937 10.0 BNBForm allows remote attackers to read arbitrary files via the automessage h... CVE-2025-32510 10.0 Unrestricted Upload of File with Dangerous Type vulnerability in ovatheme Ova... CVE-2024-6500 10.0 The InPost for WooCommerce plugin and InPost PL plugin for WordPress are vuln...
View all Files CVEs →

This Vulnerability Is Being Actively Exploited

CVE-2026-34909 is on the CISA KEV list - confirmed active exploitation in the wild. BreachSpider alerts your team within 15 minutes when KEV vulnerabilities match your ICS assets.

Start Free KEV Monitoring →