Security Advisory Bulletin 064
33.24K views
1 replies
Edited4 hours ago
Activity4 hours ago
Overview
Published: May 21, 2026
Updated: May 22, 2026
Version: 1.1
Revision: 1.1
Summary 1 of 5
A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.
Affected Products:
UniFi OS Server (Version 5.0.6 and earlier)
Mitigation:
Update your UniFi OS Server to Version 5.0.8 or later
Impact:
CVSS v3.0 Severity and Metrics:
Base Score: 9.1 Critical
Vector:
CVSS: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CVE: CVE-2026-33000 (V3rlust)
Summary 2 of 5
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized changes to the system.
Affected Products:
UCG-Industrial (Version 5.0.13 and earlier)
UDM, UDM-Pro, UDM-SE, UDM-Pro-Max, EFG, UDW, UDR, UDR7, Express 7, UNVR, UNVR-Pro, UNVR-Instant, ENVR, UCG-Ultra, UCG-Max and UCG-Fiber (Version 5.0.16 and earlier)
UDR-5G, ENVR-Core, UCKP, UCK and UCK-Enterprise (Version 5.0.17 and earlier)
UniFi OS Server (Version 5.0.6 and earlier)
UNVR-G2 and UNVR-G2-Pro (Version 5.1.11 and earlier)
UDM-Beast, UNAS-2, UNAS-4, UNAS-Pro, UNAS-Pro-4 and UNAS-Pro-8 (Version 5.1.8 and earlier)
Mitigation:
Update your UCG-Industrial to Version 5.1.12 or later.
Update your UDM, UDM-Pro, UDM-SE, UDM-Pro-Max, EFG, UDW, UDR, UDR7, Express 7, UNVR, UNVR-Pro, UNVR-Instant, ENVR, UCG-Ultra, UCG-Max and UCG-Fiber to Version 5.1.12 or later.
Update your UDR-5G, ENVR-Core, UCKP, UCK and UCK-Enterprise to Version 5.1.12 or later.
Update your UniFi OS Server to Version 5.0.8 or later.
Update your UNVR-G2 and UNVR-G2-Pro to Version 5.1.12 or later.
Update your UNAS-2, UNAS-4, UNAS-Pro, UNAS-Pro-4 and UNAS-Pro-8 to Version 5.1.10 or later.
Update your UDM-Beast 5.1.11 or later.
Impact:
CVSS v3.0 Severity and Metrics:
Base Score: 10.0 Critical
Vector:
CVSS: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVE: CVE-2026-34908 (Duc Anh Nguyen (@heckintosh_))
Summary 3 of 5
A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to access an underlying account.
Affected Products:
UCG-Industrial (Version 5.0.13 and earlier)
UDM, UDM-Pro, UDM-SE, UDM-Pro-Max, EFG, UDW, UDR, UDR7, Express 7, UNVR, UNVR-Pro, UNVR-Instant, ENVR, UCG-Ultra, UCG-Max and UCG-Fiber (Version 5.0.16 and earlier)
UDR-5G, ENVR-Core, UCKP, UCK and UCK-Enterprise (Version 5.0.17 and earlier)
UniFi OS Server (Version 5.0.6 and earlier)
UNVR-G2 and UNVR-G2-Pro (Version 5.1.11 and earlier)
UDM-Beast, UNAS-2, UNAS-4, UNAS-Pro, UNAS-Pro-4 and UNAS-Pro-8 (Version 5.1.8 and earlier)
Express (Version 4.0.13 and earlier)
Mitigation:
Update your UCG-Industrial to Version 5.1.12 or later.
Update your UDM, UDM-Pro, UDM-SE, UDM-Pro-Max, EFG, UDW, UDR, UDR7, Express 7, UNVR, UNVR-Pro, UNVR-Instant, ENVR, UCG-Ultra, UCG-Max and UCG-Fiber to Version 5.1.12 or later.
Update your UDR-5G, ENVR-Core, UCKP, UCK and UCK-Enterprise to Version 5.1.12 or later.
Update your UniFi OS Server to Version 5.0.8 or later.
Update your UNVR-G2 and UNVR-G2-Pro to Version 5.1.12 or later.
Update your UNAS-2, UNAS-4, UNAS-Pro, UNAS-Pro-4 and UNAS-Pro-8 to Version 5.1.10 or later.
Update your UDM-Beast 5.1.11 or later.
Update your Express to Version 4.0.14 or later.
Impact:
CVSS v3.0 Severity and Metrics:
Base Score: 10.0 Critical
Vector:
CVSS: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVE: CVE-2026-34909 (Abdulaziz Almadhi | Catchify Security)
Summary 4 of 5
A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.
Affected Products:
UCG-Industrial (Version 5.0.13 and earlier)
UDM, UDM-Pro, UDM-SE, UDM-Pro-Max, EFG, UDW, UDR, UDR7, Express 7, UNVR, UNVR-Pro, UNVR-Instant, ENVR, UCG-Ultra, UCG-Max and UCG-Fiber (Version 5.0.16 and earlier)
UDR-5G, ENVR-Core, UCKP, UCK and UCK-Enterprise (Version 5.0.17 and earlier)
UniFi OS Server (Version 5.0.6 and earlier)
UNVR-G2 and UNVR-G2-Pro (Version 5.1.11 and earlier)
UDM-Beast, UNAS-2, UNAS-4, UNAS-Pro, UNAS-Pro-4 and UNAS-Pro-8 (Version 5.1.8 and earlier)
Mitigation:
Update your UCG-Industrial to Version 5.1.12 or later.
Update your UDM, UDM-Pro, UDM-SE, UDM-Pro-Max, EFG, UDW, UDR, UDR7, Express 7, UNVR, UNVR-Pro, UNVR-Instant, ENVR, UCG-Ultra, UCG-Max and UCG-Fiber to Version 5.1.12 or later.
Update your UDR-5G, ENVR-Core, UCKP, UCK and UCK-Enterprise to Version 5.1.12 or later.
Update your UniFi OS Server to Version 5.0.8 or later.
Update your UNVR-G2 and UNVR-G2-Pro to Version 5.1.12 or later.
Update your UNAS-2, UNAS-4, UNAS-Pro, UNAS-Pro-4 and UNAS-Pro-8 to Version 5.1.10 or later.
Update your UDM-Beast 5.1.11 or later.
Impact:
CVSS v3.0 Severity and Metrics:
Base Score: 10.0 Critical
Vector:
CVSS: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVE: CVE-2026-34910 (John Carroll)
Summary 5 of 5
A malicious actor with access to the network and low privileges could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to obtain sensitive information.
Affected Products:
UCG-Industrial (Version 5.0.13 and earlier)
UDM, UDM-Pro, UDM-SE, UDM-Pro-Max, EFG, UDW, UDR, UDR7, Express 7, UNVR, UNVR-Pro, UNVR-Instant, ENVR, UCG-Ultra, UCG-Max and UCG-Fiber (Version 5.0.16 and earlier)
UDR-5G, ENVR-Core, UCKP, UCK and UCK-Enterprise (Version 5.0.17 and earlier)
UniFi OS Server (Version 5.0.6 and earlier)
UNVR-G2 and UNVR-G2-Pro (Version 5.1.11 and earlier)
UDM-Beast, UNAS-2, UNAS-4, UNAS-Pro, UNAS-Pro-4 and UNAS-Pro-8 (Version 5.1.8 and earlier)
Mitigation:
Update your UCG-Industrial to Version 5.1.12 or later.
Update your UDM, UDM-Pro, UDM-SE, UDM-Pro-Max, EFG, UDW, UDR, UDR7, Express 7, UNVR, UNVR-Pro, UNVR-Instant, ENVR, UCG-Ultra, UCG-Max and UCG-Fiber to Version 5.1.12 or later.
Update your UDR-5G, ENVR-Core, UCKP, UCK and UCK-Enterprise to Version 5.1.12 or later.
Update your UniFi OS Server to Version 5.0.8 or later.
Update your UNVR-G2 and UNVR-G2-Pro to Version 5.1.12 or later.
Update your UNAS-2, UNAS-4, UNAS-Pro, UNAS-Pro-4 and UNAS-Pro-8 to Version 5.1.10 or later.
Update your UDM-Beast 5.1.11 or later.
Impact:
CVSS v3.0 Severity and Metrics:
Base Score: 7.7 High
Vector:
CVSS: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
CVE: CVE-2026-34911 (Hakai Security)