PoC Archive PoC Archive

tag

Unauth

  • CVE-2026-34910, CVE-2026-34909, CVE-2026-34908 network CRITICAL 10 KEV EPSS 87%

    UniFi OS -- Unauthenticated Command Injection RCE (CVE-2026-34910)

    CVE-2026-34910 is an unauthenticated command injection vulnerability in Ubiquiti UniFi OS Server, rated CVSS 10.0 and listed in CISA KEV. The nginx auth layer treats any request whose raw URI starts with /api/auth/validate-sso/ as public, but routes by the…

    Patched 2026-08-16