[CVE-2026-34908] Popping Root on UniFi OS Server: Unauthenticated RCE Chain Detection & Analysis
bishopfox.com | blog | CVE-2026-34908 | #rce | #vulnerability-research | #command-injection | #unifi | #ubiquiti | #cve-2026-34908
Summary
Bishop Fox confirms an unauthenticated chain across UniFi OS flaws — CVE-2026-34908/34909 plus a package-update command injection — yielding root in one request; patch UOS 5.0.8+ and rotate secrets.
- Published
- Collected
Skip to content