Latest Ubiquiti UniFi Network Application vulnerabilities #
Ubiquiti disclosed multiple vulnerabilities affecting certain versions of the UniFi Network Application:
- A path traversal vulnerability. Successful exploitation allows a network, unauthenticated adversary to access files on the underlying system that could be manipulated to access an underlying account. The vulnerability has been designated CVE-2026-22557 and has been rated critical with a CVSS score of 10.0.
- A NoSQL injection vulnerability. Successful exploitation allows a network, authenticated adversary to escalate privileges. The vulnerability has been designated CVE-2026-22558 and has been rated high with a CVSS score of 7.7.
The following versions are affected
- UniFi Network Application versions 10.1.85 and earlier
- UniFi Network Application versions 10.2.93 and earlier
- UniFi Network Application versions 9.0.114 and earlier
What is Ubiquiti UniFi Network Application? #
UniFi Network Application provides centralized management for scaling and optimizing network performance, security,and device configuration across enterprise, SOHO, or home networks.
What is the impact? #
Successful exploitation of the vulnerabilities could allow an adversary to gain unauthorized access to the UniFi Network Application compromising the overall system integrity.
Are updates or workarounds available? #
Users are encouraged to update to the latest version as quickly as possible:
- UniFi Network Application versions 10.1.89 or later
- UniFi Network Application versions 10.2.97 or later.
- UniFi Express firmware to 4.0.13 or later, which updates the UniFi Network Application to version 9.0.118 or later.
How to find potentially vulnerable systems with runZero #
From the Software Inventory, use the following query to locate potentially impacted assets:
vendor:Ubiquiti AND product:"UniFi Network"