Skip to content
You can now search across every topic, entity and event.What's new
UniFi OS Server
ProductUS

UniFi OS Server

Ubiquiti's management software for Dream Machine and Cloud Key appliances; three CVSS-10 flaws patched June 2026.

UniFi OS Server, Ubiquiti's management software for its network appliances, carried three maximum-severity flaws that together let an outsider reach root with no login, until a 23 June 2026 fix landed in version 5.0.8.

Last refreshed: 3 August 2026 · Appears in 1 active topic

Key Question

What does a chained CVSS-10 exploit mean for businesses running older UniFi versions?

Timeline for UniFi OS Server

#12 28 Jul

Mentioned in: KEV patch clocks fell to three days

Cybersecurity: Threats and Defences
#8 23 Jun

Exposed unauthenticated root via three-CVE chain until version 5.0.8

Cybersecurity: Threats and Defences: Triple CVSS-10 Ubiquiti chain hits root
View full timeline →

Background

UniFi OS Server is Ubiquiti's management software for its Dream Machine and Cloud Key network appliances, the control layer administrators use to configure and monitor UniFi-based networks.

Because it runs on appliances deployed at scale across small business and managed-service-provider networks, flaws in UniFi OS Server carry a wide blast radius: a single vulnerability class can expose a very large population of devices simultaneously.

As the software layer shared across an entire appliance family, UniFi OS Server updates typically apply fleet-wide once an administrator pushes them, which can make a single patch release consequential across many devices at once. It is maintained by Ubiquiti and is not sold or licensed separately from the appliances it manages.

Key Issues
Root exploit chain

Three flaws in UniFi OS gave root

Three separate weaknesses sat in UniFi OS Server before 23 June 2026: a way past its access controls, a way to reach files outside their intended directory, and a way to run arbitrary commands, each independently rated the maximum CVSS 10.0. Chained together they gave an outsider root on the device without ever logging in, and CISA listed all three in its KEV catalogue the same day under a three-day Deadline, the first live use of BOD 26-04's top tier.

Ubiquiti shipped the fix in UniFi OS Server 5.0.8, but the software runs across Dream Machine and Cloud Key appliances deployed at millions of small businesses and managed service providers, where updating within three days of disclosure is rarely realistic.

Common Questions
What are CVE-2026-34908 CVE-2026-34909 CVE-2026-34910 in UniFi OS Server?
The three flaws are an access-control bypass (CVE-2026-34908), a PATH traversal (CVE-2026-34909), and a command injection (CVE-2026-34910), each scored CVSS 10.0. Bishop Fox chained all three to demonstrate unauthenticated root access. All are patched in UniFi OS Server 5.0.8.Source: Bishop Fox advisory, 23 June 2026
How do I update UniFi OS Server to fix the Bishop Fox vulnerabilities?
Update to UniFi OS Server 5.0.8 via the UniFi OS dashboard's system update screen or the Ubiquiti release notes page. CISA set a federal Deadline of 26 June 2026 for government systems; all administrators should treat the update as urgent regardless.Source: Ubiquiti release notes, June 2026
Which Ubiquiti devices run UniFi OS Server?
UniFi OS Server runs on Ubiquiti Dream Machine Pro, Dream Machine SE, Dream Machine Pro Max, Cloud Key Gen2, and Cloud Key Gen2 Plus. These are the management appliances used to control UniFi access points, switches, and cameras.Source: Ubiquiti product documentation
Can an attacker exploit UniFi OS Server without valid credentials?
Yes, on versions before 5.0.8. Bishop Fox's public demo showed that the CVE-2026-34908/34909/34910 chain reaches root with no authentication. A detection script was also published, meaning the barrier to exploitation is very low for any attacker with network access to the management interface.Source: Bishop Fox advisory, 23 June 2026
Source Material