CVE-2026-34911: Path Traversal
Published May 22, 2026
·Updated
A malicious actor with access to the network and low privileges could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to obtain sensitive information.
Affected Software
62 affected components
Ubiquiti UniFi OS
UI Unifi Os Server<5.0.8
All of the following
UI Unifi Cloud Gateway Industrial Firmware<5.1.12
UI Unifi Cloud Gateway Industrial
All of the following
UI Unifi Dream Machine Firmware<5.1.12
UI Unifi Dream Machine
All of the following
UI Unifi Dream Machine Pro Firmware<5.1.12
UI UniFi Dream Machine Pro
All of the following
UI Unifi Dream Machine Special Edition Firmware<5.1.12
UI Unifi Dream Machine Special Edition
All of the following
UI Unifi Dream Machine Pro Max Firmware<5.1.12
UI Unifi Dream Machine Pro Max
All of the following
UI Enterprise Fortress Gateway Firmware<5.1.12
UI Enterprise Fortress Gateway
All of the following
UI Unifi Dream Wall Firmware<5.1.12
UI Unifi Dream Wall
All of the following
UI Unifi Dream Router Firmware<5.1.12
UI Unifi Dream Router
All of the following
UI Unifi Dream Router 7 Firmware<5.1.12
UI Unifi Dream Router 7
All of the following
UI Unifi Express 7 Firmware<5.1.12
UI Unifi Express 7
All of the following
UI Unifi Network Video Recorder Firmware<5.1.12
UI Unifi Network Video Recorder
All of the following
UI Unifi Network Video Recorder Pro Firmware<5.1.12
UI Unifi Network Video Recorder Pro
All of the following
UI Unifi Network Video Recorder Instant Firmware<5.1.12
UI Unifi Network Video Recorder Instant
All of the following
UI Enterprise Network Video Recorder Firmware<5.1.12
UI Enterprise Network Video Recorder
All of the following
UI Unifi Cloud Gateway Ultra Firmware<5.1.12
UI Unifi Cloud Gateway Ultra
All of the following
UI Unifi Cloud Gateway Max Firmware<5.1.12
UI Unifi Cloud Gateway Max
All of the following
UI Unifi Cloud Gateway Fiber Firmware<5.1.12
UI Unifi Cloud Gateway Fiber
All of the following
UI Unifi Dream Router 5g Max Firmware<5.1.12
UI Unifi Dream Router 5g Max
All of the following
UI Enterprise Network Video Recorder Core Firmware<5.1.12
UI Enterprise Network Video Recorder Core
All of the following
UI Unifi Cloud Key Plus Firmware<5.1.12
UI Unifi Cloud Key Plus
All of the following
UI Unifi Cloudkey Firmware<5.1.12
UI Unifi Cloudkey
All of the following
UI Unifi Cloudkey Enterprise Firmware<5.1.12
UI Unifi Cloudkey Enterprise
All of the following
UI Unifi Network Video Recorder G2 Firmware<5.1.12
UI Unifi Network Video Recorder G2
All of the following
UI Unifi Network Video Recorder G2 Pro Firmware<5.1.12
UI Unifi Network Video Recorder G2 Pro
All of the following
UI Unifi Dream Machine Beast Firmware<5.1.11
UI Unifi Dream Machine Beast
All of the following
UI Unas 2 Firmware<5.1.10
UI Unas 2
All of the following
UI Unas 4 Firmware<5.1.10
UI Unas 4
All of the following
UI Unas Pro Firmware<5.1.10
UI Unas Pro
All of the following
UI Unas Pro 4 Firmware<5.1.10
UI Unas Pro 4
All of the following
UI Unas Pro 8 Firmware<5.1.10
UI Unas Pro 8
Remediation
Event History
May 22, 2026
CVE Published
via MITRE·12:43 AM
Data Sourced
via MITRE·12:43 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:16 AM
RemedyDescriptionSeverityWeaknessAffected Software
News Published
via BleepingComputer·12:00 PM
News Published
via BleepingComputer·12:03 PM
Frequently Asked Questions
1
What is the severity of CVE-2026-34911?
CVE-2026-34911 has a severity rating of high at 7.7.
2
How can I fix CVE-2026-34911?
To fix CVE-2026-34911, ensure that your Ubiquiti UniFi OS devices are updated to the latest security version provided by Ubiquiti.
3
What type of vulnerability is CVE-2026-34911?
CVE-2026-34911 is classified as a Path Traversal vulnerability.
4
What are the potential impacts of exploiting CVE-2026-34911?
Exploitation of CVE-2026-34911 can lead to unauthorized access to sensitive files on the underlying system.
5
Who is affected by CVE-2026-34911?
CVE-2026-34911 affects users of Ubiquiti UniFi OS devices with network access and low privileges.