ZeroHour
CyberScooppublished ()ingested @CyberScoopNews

Ubiquiti defect poses account takeover risk for UniFi Networking Application users

criticalExploit / PoC exploited in the wildimportance 60CVE-2026-22557CVE-2026-22558

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-22557
Path Traversal in Ubiquiti UniFi Network Application Enables Account Access

CVE-2026-22557 is a path traversal flaw (CWE-22) in the UniFi Network Application that lets an attacker reach files on the underlying operating system of the controller host. It is triggered by crafted network requests that traverse outside the application's intended directory, and per the CVSS vector it requires no authentication, no user interaction, and is reachable over the network. By reading files that contain credentials or account data on the underlying system, an attacker can pivot to gain access to an underlying account, creating an account-takeover risk. Any organization running a UniFi Network Application — whether self-hosted on servers or running on UniFi OS consoles — is potentially affected. No public proof-of-concept or confirmed in-the-wild exploitation is known yet, but the 28.1% EPSS score (98th percentile) indicates an elevated likelihood of exploitation within the next 30 days.

Do: Update UniFi Network Application to the latest patched release referenced in Ubiquiti's advisory (affected version ranges are not specified in the data provided). Restrict management-interface access to trusted networks or a VPN rather than exposing it to the internet, and check controller hosts for unexpected file access. Because the flaw can expose underlying account credentials, consider rotating local administrator credentials for exposed controllers if compromise is suspected.

10.028%
  • Ubiquiti UniFi Network Application
mass≈1M+ deployments (self-hosted controllers plus UniFi OS consoles running the Network Application)
CVE-2026-22558
An Authenticated NoSQL Injection vulnerability found in UniFi Network Application could allow a malicious actor with authenticated access to the network to esca

An Authenticated NoSQL Injection vulnerability found in UniFi Network Application could allow a malicious actor with authenticated access to the network to escalate privileges.

NVD description · AI analysis pending
7.7<1%
Full article526 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

The maximum-severity vulnerability, which hasn’t been exploited in the wild yet, affects software customers use to manage networking devices.

Listen to this article

0:00

Learn more.

(Getty Images)

Researchers and threat hunters are scrambling to contain a maximum-severity defect in Ubiquiti’s UniFi Network Application that attackers could exploit to take over user accounts by accessing and manipulating files.

The path-traversal vulnerability — CVE-2026-22557 — affects software used to manage UniFi networking devices, including access points, gateways and switches. The vendor disclosed and released patches for the defect in a security advisory Wednesday.

“As of this morning, we have not observed any public proof-of-concept exploits or confirmed reports of exploitation in the wild,” Matthew Guidry, senior product detection engineer at Censys, told CyberScoop.

“However, because this is a path-traversal vulnerability, the technical complexity for an attacker is typically lower than memory-corruption or buffer-overflow bugs,” he added. “Given that the CVSS 10 rating implies low attack complexity, we anticipate that once the specific vulnerable endpoint is identified, exploitation will be trivial to automate.”

Censys sensors observed nearly 88,000 UniFi Network Application hosts publicly exposed to the internet as of Friday morning. The software doesn’t expose what version it’s running, so scans cannot distinguish between vulnerable and patched instances.

Roughly one-third of the exposed instances of UniFi Network Application are located in the United States. 

As a defender, when you see a CVSS 10 for a product you immediately recognize and know is everywhere, you probably get a bit anxious,” Guidry said. “You also know it’s remotely exploitable, requires no authentication, and needs no user interaction, because it wouldn’t be a 10 if it wasn’t. Ubiquiti is a name you hear frequently, and many of those devices are sitting directly on the internet.”

Ubiquiti advises UniFi Network Application users to update to the latest software versions, which also addressed a second vulnerability — CVE-2026-22558 — that attackers could exploit to escalate privileges.

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/ubiquiti-unifi-networking-application-vulnerability/