CVE-2026-34908
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized changes to the system.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 10
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- EPSS probability
- 85.19%
- CISA KEV
- Known exploited vulnerability
- CWE
- CWE-284
- Published
- 2026-05-22
- Last modified
- 2026-06-24
Affected products
- Ubiquiti Inc UniFi OS Server
- Ubiquiti Inc UDM
- Ubiquiti Inc UDM-Pro
- Ubiquiti Inc UDM-SE
- Ubiquiti Inc UDM-Pro-Max
- Ubiquiti Inc UDM-Beast
- Ubiquiti Inc EFG
- Ubiquiti Inc UDW
Weakness type
Related vulnerabilities
- CVE-2026-88864 — Capgo SSO Provider Authentication Bypass via PostgREST Direct Write
- CVE-2026-78084 — Joomla Extension - joomshaper.com - Missing Access Control in Gallery Image Management in SP Property < 4.1.4
- CVE-2026-50165 — alf.io has Improper Access Control for Organization Owners that Exposes System Secrets
- CVE-2026-86774 — Snipe-IT before 8.7.0 Broken Access Control via AssetModelPolicy
- CVE-2026-19625 — IBM Enterprise Build of Quarkus is affected by multiple vulnerabilities
- CVE-2026-75998 — ColdFusion | Improper Access Control (CWE-284)
- CVE-2026-86672 — ningzichun Student Management System Backup example.7z information disclosure
- CVE-2026-81963 — Windows Update Stack Elevation of Privilege Vulnerability