Known vulnerability record

CVE-2026-34910

Ubiquiti UniFi OS Improper Input Validation Vulnerability

Stable IDcve:CVE-2026-34910Last updatedLast verifiedLegacy review pendingProvenanceCISA KEV + CVE record + EPSS

Ubiquiti UniFi OS Improper Input Validation Vulnerability

Ubiquiti UniFi OS contains an improper input validation vulnerability which could allow a malicious actor with access to the network to conduct command injection.

Keep the signals separate

CVSS severitycriticalScore 10 · source hackerone
EPSS probability87.0%Probability of exploitation in the next 30 days; not severity
CISA KEVKnown exploitedAdded 2026-06-23
Ransomware useunknownPreserved as known / unknown, not a truthy default

Dates and provenance

CVE published
2026-05-22
CVE modified
2026-06-24
KEV date added
2026-06-23
Dataset fetched
2026-08-21T03:55:10.675Z

Original records

Version history: normalized permanent page created 2026-08-20. Machine-enriched fields remain source-attributed.