logo

Critical UniFi OS bug lets hackers gain root without authentication

ID: 79c02a9d-7438-5e22-becf-113df390803e

STIX ID: report--79c02a9d-7438-5e22-becf-113df390803e

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2026-06-08

Date Updated: 2026-06-08

Author: Bill Toulas

...
...

Attackers can chain three fixed UniFi OS Server vulnerabilities (CVE-2026-34908, -34909, -34910) to bypass authentication, trigger a command-injection endpoint, and achieve root on affected devices (validated by Bishop Fox on 5.0.6). Ubiquiti released fixes in 5.0.8; defenders should upgrade, run the Bishop Fox detection script, and monitor requests to /api/auth/validate-sso/ and ucs/update/latest_package, as well as suspicious ucs-update child processes and unexpected sudo activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.