ZeroHour

CVE-2026-22557

mass

Path Traversal in Ubiquiti UniFi Network Application Enables Account Access

CVSS 3.1
10.0 critical
EPSS
28%p98
Published
()
Modified
AI analysis

CVE-2026-22557 is a path traversal flaw (CWE-22) in the UniFi Network Application that lets an attacker reach files on the underlying operating system of the controller host. It is triggered by crafted network requests that traverse outside the application's intended directory, and per the CVSS vector it requires no authentication, no user interaction, and is reachable over the network. By reading files that contain credentials or account data on the underlying system, an attacker can pivot to gain access to an underlying account, creating an account-takeover risk. Any organization running a UniFi Network Application — whether self-hosted on servers or running on UniFi OS consoles — is potentially affected. No public proof-of-concept or confirmed in-the-wild exploitation is known yet, but the 28.1% EPSS score (98th percentile) indicates an elevated likelihood of exploitation within the next 30 days.

What to do: Update UniFi Network Application to the latest patched release referenced in Ubiquiti's advisory (affected version ranges are not specified in the data provided). Restrict management-interface access to trusted networks or a VPN rather than exposing it to the internet, and check controller hosts for unexpected file access. Because the flaw can expose underlying account credentials, consider rotating local administrator credentials for exposed controllers if compromise is suspected.

Affected
Ubiquiti UniFi Network Application
Estimated exposure
mass≈1M+ deployments (self-hosted controllers plus UniFi OS consoles running the Network Application) — Ubiquiti's UniFi Network Application is one of the most widely deployed WLAN/network controllers in the SMB and prosumer space, with millions of self-hosted and console-based installs, and public internet scans historically show hundreds…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A malicious actor with access to the network could exploit a Path Traversal vulnerability found in the UniFi Network Application to access files on the underlying system that could be manipulated to access an underlying account.

Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

In the news