7.7
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Description
A malicious actor with access to the network and low privileges could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to obtain sensitive information.
Basic Information
ID
CVE-2026-34911
Source
hackerone
Published
May 22, 2026 at 00:43
Affected Product
Vendor
Ubiquiti Inc
Product
UniFi OS Server
Affected Versions
Ubiquiti Inc UniFi OS Server 0
Ubiquiti Inc UDM 0
Ubiquiti Inc UDM-Pro 0
Ubiquiti Inc UDM-SE 0
Ubiquiti Inc UDM-Pro-Max 0
Ubiquiti Inc UDM-Beast 0
Ubiquiti Inc EFG 0
Ubiquiti Inc UDW 0
Ubiquiti Inc UDR 0
Ubiquiti Inc UDR7 0
Ubiquiti Inc UDR-5G 0
Ubiquiti Inc Express 7 0
Ubiquiti Inc UNVR 0
Ubiquiti Inc UNVR-Pro 0
Ubiquiti Inc UNVR-Instant 0
Ubiquiti Inc UNVR-G2 0
Ubiquiti Inc UNVR-G2-Pro 0
Ubiquiti Inc ENVR 0
Ubiquiti Inc ENVR-Core 0
Ubiquiti Inc UNAS-2 0
Ubiquiti Inc UNAS-4 0
Ubiquiti Inc UNAS-Pro 0
Ubiquiti Inc UNAS-Pro-4 0
Ubiquiti Inc UNAS-Pro-8 0
Ubiquiti Inc UCKP 0
Ubiquiti Inc UCK 0
Ubiquiti Inc UCK-Enterprise 0
Ubiquiti Inc UCG-Ultra 0
Ubiquiti Inc UCG-Max 0
Ubiquiti Inc UCG-Fiber 0
Ubiquiti Inc UCG-Industrial 0
Ubiquiti Inc UDM 0
Ubiquiti Inc UDM-Pro 0
Ubiquiti Inc UDM-SE 0
Ubiquiti Inc UDM-Pro-Max 0
Ubiquiti Inc UDM-Beast 0
Ubiquiti Inc EFG 0
Ubiquiti Inc UDW 0
Ubiquiti Inc UDR 0
Ubiquiti Inc UDR7 0
Ubiquiti Inc UDR-5G 0
Ubiquiti Inc Express 7 0
Ubiquiti Inc UNVR 0
Ubiquiti Inc UNVR-Pro 0
Ubiquiti Inc UNVR-Instant 0
Ubiquiti Inc UNVR-G2 0
Ubiquiti Inc UNVR-G2-Pro 0
Ubiquiti Inc ENVR 0
Ubiquiti Inc ENVR-Core 0
Ubiquiti Inc UNAS-2 0
Ubiquiti Inc UNAS-4 0
Ubiquiti Inc UNAS-Pro 0
Ubiquiti Inc UNAS-Pro-4 0
Ubiquiti Inc UNAS-Pro-8 0
Ubiquiti Inc UCKP 0
Ubiquiti Inc UCK 0
Ubiquiti Inc UCK-Enterprise 0
Ubiquiti Inc UCG-Ultra 0
Ubiquiti Inc UCG-Max 0
Ubiquiti Inc UCG-Fiber 0
Ubiquiti Inc UCG-Industrial 0