Skip to main content
Mallory
Critical

Improper Access Control in Ubiquiti UniFi OS authentication gateway

IdentifiersCVE-2026-34908CWE-284· Improper Access Control

CVE-2026-34908 is a critical improper access control vulnerability affecting Ubiquiti UniFi OS devices, including UniFi OS Server 5.0.6 and earlier. Available reporting describes the flaw as residing in the UniFi OS authentication gateway, where a network-accessible attacker can make unauthorized changes to the system without authentication. Supporting analysis indicates the weakness is part of an authentication-bypass condition caused by inconsistent handling of request URIs: the authentication component evaluates the raw request URI while Nginx routes requests using a normalized URI. This discrepancy can allow crafted requests to appear to target an authentication-exempt path while resolving to protected internal routes after normalization. On its own, the issue enables unauthorized system changes; in exploit chains documented by Bishop Fox, CVE-2026-34908 can be combined with CVE-2026-34909 to bypass authentication and reach internal endpoints, including a vulnerable package-update endpoint later abused via CVE-2026-34910 for command execution.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation allows an unauthenticated attacker with network access to bypass intended access restrictions and make unauthorized changes to affected UniFi OS systems. In practical terms, this can expose protected internal functionality and materially weaken the security boundary of the management plane. When chained with CVE-2026-34909 and CVE-2026-34910, the flaw contributes to unauthenticated remote code execution and eventual root compromise, which can in turn expose managed infrastructure, stored secrets, administrative session material, and systems controlled by UniFi OS such as network devices, surveillance cameras, and identity or access-management components.

Mitigation

If you can’t patch tonight, do this now.

If immediate patching is not possible, reduce exposure of UniFi OS management interfaces to untrusted networks and the public internet, restrict access to trusted administrative networks, and increase monitoring for exploitation attempts. Available guidance recommends alerting on requests containing the /api/auth/validate-sso/ prefix together with encoded traversal patterns such as ..%2f, ..%2e, or %2e%2e, as well as reviewing access to internal proxy routes and suspicious activity involving package-update functionality. Because this flaw has been shown to participate in an unauthenticated RCE chain, defenders should also review systems for evidence of unauthorized configuration changes, unexpected child processes, suspicious sudo activity, and persistence. If compromise is suspected, rotate relevant secrets and credentials after containment.

Remediation

Patch, then assume compromise.

Upgrade affected systems to vendor-fixed releases. For UniFi OS Server, available reporting states the issue is fixed in version 5.0.8 and later. More broadly, Ubiquiti issued patched UniFi OS releases across affected product lines under Security Advisory Bulletin 064. Supporting analysis indicates the vendor addressed the issue by adding URI-normalization checks in Nginx and related request-handling hardening. Organizations should apply the appropriate fixed version for each affected platform on an urgent basis and investigate for signs of prior compromise, as patching does not by itself invalidate artifacts or access obtained before remediation.
PUBLIC EXPLOITS

Exploits

No valid public exploits. Mallory filtered out 1 candidate as fakes, detection scripts, or README-only repos.

VALID 0 / 1 TOTALView more in app

All candidate exploits were filtered out by Mallory's validation.

EXPOSURE SURFACE

Affected products & vendors

Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.

VendorProductType
UbiquitiUnifi Osapplication
UbiquitiUnifi Os Serveroperating_system

Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence

Every observed campaign linking this CVE to a named adversary.

Associated malware

Malware families riding this exploit, with evidence and IOCs.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity14

Community discussion across Reddit, Mastodon, and other social sources.