CVE-2026-34908

A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized changes to the system.

Scoring

Severity
CRITICAL
CVSS base score
10
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS probability
85.19%
CISA KEV
Known exploited vulnerability
CWE
CWE-284
Published
2026-05-22
Last modified
2026-06-24

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs