Latest Ubiquiti UniFi Network Application vulnerabilities #

Ubiquiti disclosed multiple vulnerabilities affecting certain versions of the UniFi Network Application:

  • A path traversal vulnerability. Successful exploitation allows a network, unauthenticated adversary to access files on the underlying system that could be manipulated to access an underlying account. The vulnerability has been designated CVE-2026-22557 and has been rated critical with a CVSS score of 10.0.
  • A NoSQL injection vulnerability. Successful exploitation allows a network, authenticated adversary to escalate privileges. The vulnerability has been designated CVE-2026-22558 and has been rated high with a CVSS score of 7.7.

    The following versions are affected

    • UniFi Network Application versions 10.1.85 and earlier
    • UniFi Network Application versions 10.2.93 and earlier
    • UniFi Network Application versions 9.0.114 and earlier

    What is Ubiquiti UniFi Network Application? #

    UniFi Network Application provides centralized management for scaling and optimizing network performance, security,
    and device configuration across enterprise, SOHO, or home networks.

    What is the impact? #

    Successful exploitation of the vulnerabilities could allow an adversary to gain unauthorized access to the UniFi Network Application compromising the overall system integrity.

    Are updates or workarounds available? #

    Users are encouraged to update to the latest version as quickly as possible:

    • UniFi Network Application versions 10.1.89 or later
    • UniFi Network Application versions 10.2.97 or later.
    • UniFi Express firmware to 4.0.13 or later, which updates the UniFi Network Application to version 9.0.118 or later.

    How to find potentially vulnerable systems with runZero #

    From the Software Inventory, use the following query to locate potentially impacted assets:

    vendor:Ubiquiti AND product:"UniFi Network"

    Written by runZero Team

    Great research and development is a team effort! Multiple runZero team members collaborated on this post. Go team!

    More about runZero Team
    Subscribe Now

    Get the latest news and expert insights delivered in your inbox.

    Welcome to the club! Your subscription to our newsletter is successful.

    See Results in Minutes

    See & secure your total attack surface. Even the unknowns & unmanageable.