logo

Critical UniFi OS Auth Bypass Flaws Lead to Unauthenticated Root RCE

ID: eaa3a5a0-9deb-5f2f-b313-f0ed0990fccd

STIX ID: report--eaa3a5a0-9deb-5f2f-b313-f0ed0990fccd

Feed Name: GBHackers

Threat Score
92/100

Date Published: 2026-06-06

Date Updated: 2026-06-06

Author: Eswar

...
...

Ubiquiti disclosed three critical UniFi OS Server flaws (CVE-2026-34908/34909/34910) that together enable a single crafted HTTP request to gain unauthenticated root RCE; Bishop Fox demonstrated the exploit chain on version 5.0.6. Attackers can bypass the authentication gateway using percent-encoded URIs, trigger command injection in the package-update service, escalate via passwordless sudo to install malicious .deb packages, and exfiltrate persistent credentials and keys—potentially compromising network management, cloud access, databases, and physical security systems. Administrators are instructed to immediately upgrade to the fixed versions and treat externally exposed unpatched instances as fully compromised, rebuild from known-good images, and rotate keys and secrets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.