Skip to content
CVSS 10.0CVSS 10.0 · CRITICAL

CVE-2026-34908

A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized changes to the system.

View on NVD

Severity

Score: 10.0(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: CHANGED
C: HIGH
I: HIGH
A: HIGH
Weakness (CWE): CWE-284

EPSS

Probability of exploitation (next 30 days): 0.0002 (0.0%)
Percentile: 4.6%
EPSS: 2026-05-22

Technical description

A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized changes to the system.

Published: 5/22/2026, 2:16:34 AM
Last modified: 5/22/2026, 2:16:34 AM

References

HomeEventsBlogResourcesTeam