Chained UniFi OS Server flaws CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910 can give attackers root access without logging in

Researchers say attackers can take over vulnerable UniFi OS Server systems without a password and gain full root control. Bishop Fox showed that three patched bugs in UniFi OS Server 5.0.6 and earlier—CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910—can be chained from the network to bypass authentication, read files, and trigger command injection, leading to remote code execution and trivial privilege escalation via passwordless sudo.
Why it matters: UniFi OS Server can manage core business systems such as networking, cameras, and door access, so compromise can hand attackers broad control of an organization’s environment. Organizations using affected versions should patch immediately and check for suspicious requests to the noted endpoints, because the attack leaves little or no login evidence.

Sources

CISA warns of max severity Ubiquiti flaws exploited in attacks
Bill Toulas 2026.06.24 95% relevant
This updates the same UniFi OS vulnerability chain by adding that CISA has now placed CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910 in the Known Exploited Vulnerabilities catalog based on active exploitation, and that federal agencies have three days to patch or mitigate.
Critical Ubiquiti Vulnerabilities in Attackers’ Crosshairs
Ionut Arghire 2026.06.24 95% relevant
This article updates the same Ubiquiti UniFi OS vulnerability chain with concrete evidence of in-the-wild exploitation, reports of rogue 'John Sim' administrator accounts, and the key new development that CISA added all three CVEs to the KEV catalog with a three-day federal patch deadline.
Critical UniFi OS bug lets hackers gain root without authentication
Bill Toulas 2026.06.08 100% relevant
This article establishes a distinct story by surfacing a newly detailed exploit chain and defender guidance for three UniFi OS Server CVEs that together enable unauthenticated root-level remote code execution.
← Back to all stories