CVE-2026-36851 is a path traversal vulnerability in UnPoller 2.33.0 affecting processing of the password field. Crafted traversal sequences in this field can cause the application to access files outside the intended directory scope, enabling arbitrary local file reads and subsequent network exfiltration of retrieved contents.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small proof-of-concept and advisory for CVE-2026-36851 affecting UnPoller v2.33.0. It does not contain executable exploit code; instead it documents the vulnerability and provides a malicious example configuration in poc/up.conf.example. The core issue is that UnPoller accepts credential values prefixed with file:// and reads the referenced file from disk without path restriction. Those contents are then used during UniFi authentication and sent outbound in a JSON POST to the configured controller URL at /api/login. By modifying up.conf, an attacker with config write access can convert this local file-read primitive into a network exfiltration channel by pointing url to an attacker-controlled server and setting pass to a sensitive file such as file:///etc/passwd. Repository structure: README.md contains the vulnerability description, impact, exploitation steps, observed behavior, and remediation; poc/up.conf.example contains the minimal malicious configuration; .gitignore and LICENSE are non-operational. Main exploit capability: arbitrary readable file exfiltration over the network via UnPoller login requests. No RCE or persistence is demonstrated. Because the repository is primarily documentation plus a config PoC, maturity is best classified as POC.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.