Tag: UniFi OS vulnerabilities

Ubiquiti patches three max severity UniFi OS vulnerabilities
News

Ubiquiti patches three max severity UniFi OS vulnerabilities

Three maximum severity vulnerabilities in Unify OS that can be exploited by remote attackers without privileges have been patched by Ubiquiti's security upgrades. UniFi programs like UniFi Network, UniFi Protect, UniFi Access, UniFi Talk, and UniFi Connect are powered by UniFi OS, a single operating system that also aids in managing IT infrastructure, including networking, security, and other services. While the second flaw (CVE-2026-34909) allows attackers to access files on the underlying system by abusing a Path Traversal vulnerability that could be manipulated to access an underlying account, the first flaw (CVE-2026-34908) allows attackers to make unauthorized changes to targeted systems by taking advantage of an Improper Access Control weakness in Unify OS. By taking use of...