{
  "crds_version": "0.1",
  "kind": "base",
  "id": "crds:cve-2026-34908",
  "revision": 1,
  "title": "Ubiquiti UniFi OS — improper access control to system changes",
  "summary": "Ubiquiti's UniFi operating system (OS) does not check permissions properly on some actions, so anyone who can reach the device over the network can make changes to it that only an administrator should be able to make.",
  "source_type": "cve",
  "severity": "critical",
  "cvss": {
    "score": 10,
    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
    "version": "3.1"
  },
  "epss": 0.85194,
  "exploitation": {
    "known_exploited": true,
    "exploit_available": true,
    "attack_complexity": "low",
    "kev_added": "2026-06-23",
    "prerequisites": "Network access to the UniFi OS device; no credentials needed."
  },
  "remediation": {
    "patch_available": true
  },
  "mitre_attack": [
    "T1190"
  ],
  "kill_chain": "initial_access",
  "recommended_action": "Update UniFi OS per Ubiquiti Security Advisory Bulletin 064 now; review device configuration for changes you did not make and keep management off the internet.",
  "confidence": "high",
  "provenance": [
    {
      "fields": [
        "cvss",
        "exploitation.attack_complexity",
        "exploitation.exploit_available",
        "references",
        "published_at"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2026-34908",
      "retrieved_at": "2026-09-23T07:33:20.707Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "exploitation.known_exploited",
        "exploitation.kev_added"
      ],
      "source": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "retrieved_at": "2026-09-23T07:33:20.707Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "epss"
      ],
      "source": "https://api.first.org/data/v1/epss?cve=CVE-2026-34908",
      "retrieved_at": "2026-09-23T07:33:20.707Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "title",
        "summary",
        "severity",
        "remediation",
        "mitre_attack",
        "kill_chain",
        "recommended_action",
        "confidence",
        "tags",
        "exploitation.prerequisites"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2026-34908",
      "retrieved_at": "2026-09-23T07:33:20.707Z",
      "confidence": "high",
      "extractor": "claude-code"
    }
  ],
  "references": [
    {
      "type": "cve",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34908",
      "label": "NVD record"
    },
    {
      "type": "cisa",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "label": "CISA Known Exploited Vulnerabilities catalog"
    },
    {
      "type": "vendor_advisory",
      "url": "https://community.ui.com/releases/Security-Advisory-Bulletin-064-064/84811c09-4cf4-42ab-bd61-cc994445963b"
    },
    {
      "type": "exploit",
      "url": "https://www.pwndefend.com/2026/06/09/cve-2026-34910-exploitation-itw-building-a-botnet-mirai/"
    }
  ],
  "published_at": "2026-05-22T02:16:34.240Z",
  "issued_at": "2026-09-23T07:33:20.707Z",
  "tags": [
    "ubiquiti",
    "unifi",
    "access-control",
    "kev"
  ]
}
