
We just received a bounty reward from UniFi for reporting a vulnerability affecting UniFi OS devices. As part of the Hakai Labs (@HakaiOffsec) research team at @quimerax_intel, we independently identified a Path Traversal vulnerability (CVE-2026-34911) that allowed an attacker with network access to access internal routes on the underlying system without a valid token, exposing a sensitive information. Our research was conducted independently, but the vulnerability we reported could be chained with other vulnerabilities disclosed during the same period, including Improper Access Control and Command Injection flaws reported by other researchers. When combined, these issues lead to a pre-auth RCE affecting multiple UniFi OS products. Affected products include UDM, UDM-Pro, UDM-SE, UDM-Pro-Max, EFG, UDW, UDR, UDR7, Express 7, UNVR, UNVR-Pro, UNVR-Instant, ENVR, UCG-Ultra, UCG-Max, UCG-Fiber, and several other UniFi OS devices. We strongly recommend updating affected systems to the latest available version. Technical details remain under coordinated disclosure, and the only public information currently available is UniFi’s Security Advisory Bulletin. https://community.ui.com/releases/Security-Advisory-Bulletin-064-064/84811c09-4cf4-42ab-bd61-cc994445963b
Post summary
Researchers disclosed a Path Traversal vulnerability (CVE‑2026‑34911) that could lead to pre‑authentication RCE when chained with other flaws, listing affected UniFi OS devices and recommending a patch via the latest firmware update.


