Critical Known exploited (KEV) CVE-2026-34910

Command injection via input-validation flaw in Ubiquiti UniFi OS (CVE-2026-34910) — the chain's decisive blow; one of three added the same day

Ubiquiti UniFi OS Added to KEV Jun 23, 2026 Federal remediation due 2026-06-26

An improper-input-validation flaw (CWE-20) in Ubiquiti UniFi OS. A network-adjacent attacker can conduct command injection (running arbitrary commands on the device). On June 23, 2026, CISA added three UniFi OS flaws at once; remediation due three days later. Official NVD score: CVSS 10.0 (CRITICAL).

Key facts

  • CVE IDCVE-2026-34910
  • CVSS base score10 CRITICAL
  • CVSS vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
  • Affected (vendor / product)Ubiquiti UniFi OS
  • CWECWE-20
  • ExploitationListed in CISA KEV (exploitation confirmed)
  • Remediation due2026-06-26 (U.S. federal civilian agencies, BOD 22-01)

Key points

  • Improper input validation (CWE-20) in Ubiquiti UniFi OS — command injection runs arbitrary commands on the device
  • Official NVD score: CVSS 10.0 (CRITICAL)
  • On June 23, 2026, CISA added three UniFi OS flaws at once; deadline June 26 (3 days)
  • The chain's "decisive blow": access-control break → path traversal → this (command execution)
  • Command execution on the device leads to eavesdropping, tampering, lateral movement, and persistence

Command injection is a flaw in which commands slipped into an input field or request are executed by the system directly as OS commands. Without sufficient validation and sanitization of input, an attacker can run arbitrary commands on the device — effectively taking it over. This flaw makes that possible in Ubiquiti UniFi OS and represents the gravest endpoint of impact: arbitrary command execution on the device.

Lined up as stages among the three that entered KEV the same day, this is the chain's decisive blow. Open the door via CVE-2026-34908 (breaking access control), reach inside via CVE-2026-34909 (path traversal), then run arbitrary commands via this one (command injection). The CWEs differ, but against the same target — a widely deployed networking OS — each stage of privilege escalation appeared at once.

CISA imposing a single 3-day deadline on all three reflects the danger of the combination.

Command execution on networking gear leads directly to eavesdropping and tampering of traffic, lateral movement to other devices, and establishing a persistent foothold. The response is to close all three together, not individually, and to verify the management console is not exposed externally.

Why it matters

Arbitrary command execution on networking gear has wide impact — from eavesdropping and tampering to lateral movement and persistence. As the chain's decisive blow, UniFi operators must update all three as a set. "Widely deployed gear × multiple types at once × 3-day deadline" is a combination of signals that belongs at the very top of the KEV pile.

FAQ

What is command injection?
A flaw where commands slipped into input are executed by the system directly as OS commands. With insufficient validation/sanitization, an attacker can run arbitrary commands on the device.
Why handle all three together?
Access control, path traversal, and input validation in the same UniFi OS entered KEV the same day; combined they form a chain from entry to command execution. Closing one while others remain leaves the risk.
What should I do?
Update all three same-day flaws promptly per Ubiquiti's guidance. CISA requires BOD 26-04-based prioritization. Also reconsider external exposure of the management console.

Sources (primary)

This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.

#Ubiquiti#UniFi#Networking gear#Command injection#CWE-20#KEV
Disclaimer: This site independently summarizes and classifies information based on official data sources. Always verify the latest and accurate information with the official sources. Content on finance, health, legal, and security is information, not advice. This site is not an official website of the U.S. government.