UniFi Product Security Update Advisory

UniFi Product Security Update Advisory

Overview


A security update has been released to address vulnerabilities in UniFi products. Users of the affected products should update to the latest version.

Identified Vulnerabilities


  • CVE-2026-33000: A command injection vulnerability in UniFi OS (a vulnerability that could allow a threat actor to perform arbitrary command execution).
  • CVE-2026-34908: An access control flaw in UniFi OS.
  • CVE-2026-34909: A path traversal vulnerability in UniFi OS (a vulnerability that allows access to files in unintended paths).
  • CVE-2026-34910: A command injection vulnerability in UniFi OS.
  • CVE-2026-34911: A Path traversal vulnerability in UniFi OS.

Affected Products and Versions


  • UniFi OS Server: Versions 5.0.6 And earlier are affected.
  • UCG-Industrial: Versions 5.0.13 And earlier are affected.
  • UDM, UDM-Pro, UDM-SE, UDM-Pro-Max, EFG, UDW, UDR, UDR7, Express 7, UNVR, UNVR-Pro, UNVR-Instant, ENVR, UCG-Ultra, UCG-Max, UCG-Fiber: Versions 5.0.16 And earlier are affected.
  • UDR-5G, ENVR-Core, UCKP, UCK, UCK-Enterprise: Versions 5.0.17 And earlier are affected.
  • UNVR-G2, UNVR-G2-Pro: Versions 5.1.11 And earlier are affected.
  • UDM-Beast, UNAS-2, UNAS-4, UNAS-Pro, UNAS-Pro-4, UNAS-Pro-8: Versions 5.1.8 And earlier are affected.
  • Express: Versions 4.0.13 And earlier are affected.

Fixed Versions


  • CVE-2026-33000 is fixed in UniFi OS Server 5.0.8 And later.
  • CVE-2026-34908, CVE-2026-34910, and CVE-2026-34911 are resolved in versions 5.1.12 Or later for UCG-Industrial, the UDM series, UDR-5G, ENVR-Core, UCKP, UCK, UCK-Enterprise, UniFi OS Server, UNVR-G2, and UNVR-G2-Pro starting with version 5.1.12.
  • UDM-Beast is resolved in version 5.1.11 Or later.
  • UNAS-2, UNAS-4, UNAS-Pro, UNAS-Pro-4, and UNAS-Pro-8 are patched in version 5.1.10 Or later.
  • CVE-2026-34909 is patched in Express version 4.0.14 Or later.

Note


According to the official Security Advisory Bulletin 064, you must update to the latest version with the Vulnerability Patch.