news.mlab.sh
Back to the feed
vulnerability

Critical UniFi OS bug lets hackers gain root without authentication

Critical
Summary

A critical vulnerability in UniFi OS Server versions 5.0.6 and earlier allows attackers to gain root access without authentication by chaining three previously identified flaws. This vulnerability, detailed by Bishop Fox, enables remote code execution and privilege escalation, posing a significant risk to organizations using UniFi OS Server. The vendor has released a detection tool and recommends upgrading to version 5.0.8 or later to mitigate the risk.

This security issue involves a chain of vulnerabilities within the UniFi OS Server, primarily affecting versions 5.0.6 and earlier. The vulnerabilities – CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910 – allow an attacker to execute remote code with root privileges without requiring any authentication credentials. Bishop Fox researchers successfully demonstrated this attack chain, highlighting the potential for significant compromise. The root cause lies in a mismatch between how UniFi OS validates incoming requests and how Nginx routes them, creating an opportunity for attackers to bypass authentication and access backend services. Once inside, attackers can leverage a command injection flaw to execute arbitrary commands under a privileged service account with passwordless sudo access, leading to a trivial escalation to root. The vulnerability is particularly concerning due to UniFi OS Server's role as the management plane for a network, controlling access to physical devices and sensitive data.

Read the full article at BleepingComputer