LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-34908: Ubiquiti UniFi OS Improper Access Control Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jun 23, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jun 26, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-34908 to its Known Exploited Vulnerabilities catalog on Jun 23, 2026, with a federal patch deadline of Jun 26, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Ubiquiti UniFi OS contains an improper access control vulnerability which could allow a malicious actor with access to the network to make unauthorized changes to the system.

Ubiquiti UniFi OS contains an improper access control vulnerability. A malicious actor who already has access to the network could use it to make unauthorized changes to the system. This class of flaw affects devices that enforce network management functions, where an attacker positioned on the same network can alter configurations or permissions that should be restricted.

How it works

The weakness is categorized as CWE-284, improper access control. In this product class the software fails to enforce authorization checks for certain operations when requests originate from the local network.

Am I affected? How to find it in your systems

Ubiquiti UniFi OS typically runs on UniFi gateways, controllers, and related network appliances that provide centralized management. Inventory all devices in your environment that run this operating system.

How to remediate

Apply mitigations in accordance with vendor instructions. Ensure compliance with CISA BOD 26-04 guidance on prioritizing security updates based on risk and with CISA forensics triage requirements.

If you can't patch immediately

Until the vendor update can be applied, reduce the attack surface through network controls and monitoring.

If your data may have been exposed

Improper access control vulnerabilities that permit unauthorized changes have been observed in breach investigations. Organizations can run a free exposure scan of their email addresses against known breach data to check for prior incidents involving their domains.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedUbiquiti · UniFi OS
WeaknessCWE-284
Added to CISA KEVJun 23, 2026
Federal patch deadlineJun 26, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities