Junglewise Threat Intelligence

CVE-2026-34910: Ubiquiti UniFi OS command injection via improper input validation

CVE-2026-34910 · Severity: critical · CVSS 10 · Exploited in the wild · Published 2026-05-22

Technologies: Ubiquiti UniFi OS. Vendors: Ubiquiti Inc, Ubiquiti.

Executive brief

Ubiquiti UniFi OS, the operating system used to manage UniFi networking and security devices, contains a critical vulnerability. A malicious actor on the network can exploit this flaw to take full control of the device without needing a password. This could lead to a complete compromise of the network infrastructure, data theft, or service disruption.

Technical details

An improper input validation vulnerability (CWE-20) exists in multiple Ubiquiti UniFi OS devices, including the Dream Machine (UDM) and UniFi Next-Generation Gateway (EFG) lines. The flaw allows for remote command injection via the network without authentication. An attacker can exploit this to execute arbitrary system commands with elevated privileges, potentially leading to a full system compromise. The vulnerability is addressed in UniFi OS Server version 5.0.8 and various device-specific firmware versions (e.g., 5.1.12 for most UDM models).

Affected products

  • Ubiquiti Inc UniFi OS Server < 5.0.8
  • Ubiquiti Inc UDM < 5.1.12
  • Ubiquiti Inc UDM-Pro < 5.1.12
  • Ubiquiti Inc UDM-SE < 5.1.12
  • Ubiquiti Inc UDM-Pro-Max < 5.1.12
  • Ubiquiti Inc UDM-Beast < 5.1.11
  • Ubiquiti Inc EFG < 5.1.12
  • Ubiquiti Inc UDW < 5.1.12
  • Ubiquiti Inc UDR < 5.1.12
  • Ubiquiti Inc UDR7 < 5.1.12
  • Ubiquiti Inc UDR-5G < 5.1.12
  • Ubiquiti Inc Express 7 < 5.1.12

Timeline

  • 2026-05-21: disclosed: Initial report via HackerOne
  • 2026-05-21: advisory: NVD Published Date
  • 2026-06-23: advisory: Advisory publication date

Related threats