CVE-2026-34910
A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 10
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- EPSS probability
- 87.47%
- CISA KEV
- Known exploited vulnerability
- CWE
- CWE-20
- Published
- 2026-05-22
- Last modified
- 2026-06-24
Affected products
- Ubiquiti Inc UniFi OS Server
- Ubiquiti Inc UDM
- Ubiquiti Inc UDM-Pro
- Ubiquiti Inc UDM-SE
- Ubiquiti Inc UDM-Pro-Max
- Ubiquiti Inc UDM-Beast
- Ubiquiti Inc EFG
- Ubiquiti Inc UDW
Weakness type
Related vulnerabilities
- CVE-2026-13745 — Arbitrary Code Execution in Gemini CLI via Symlinked Environment Variables
- CVE-2026-54694 — NationalSecurityAgency/skills-service has Stored XSS via User Registration Enabling Admin Account Takeover
- CVE-2026-86768 — Snipe-IT before 8.7.0 Improper Input Validation via API Checkout
- CVE-2025-71417 — PocketMine-MP before 5.32.1 Denial of Service via ResourcePackClientResponsePacket
- CVE-2024-58380 — PocketMine-MP before 5.11.2 Denial of Service via BookEditPacket
- CVE-2023-54393 — PocketMine-MP before 4.20.5 Denial of Service via LoginPacket
- CVE-2023-54392 — PocketMine-MP before 4.22.3 Denial of Service via BlockActorDataPacket
- CVE-2026-74761 — Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Spoofing of RemoveSubscription clientId