Critical Ubiquiti UniFi UniFi security flaw allows potential account hijacking
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-22557 | Path Traversal in Ubiquiti UniFi Network Application Enables Account Access CVE-2026-22557 is a path traversal flaw (CWE-22) in the UniFi Network Application that lets an attacker reach files on the underlying operating system of the controller host. It is triggered by crafted network requests that traverse outside the application's intended directory, and per the CVSS vector it requires no authentication, no user interaction, and is reachable over the network. By reading files that contain credentials or account data on the underlying system, an attacker can pivot to gain access to an underlying account, creating an account-takeover risk. Any organization running a UniFi Network Application — whether self-hosted on servers or running on UniFi OS consoles — is potentially affected. No public proof-of-concept or confirmed in-the-wild exploitation is known yet, but the 28.1% EPSS score (98th percentile) indicates an elevated likelihood of exploitation within the next 30 days. Do: Update UniFi Network Application to the latest patched release referenced in Ubiquiti's advisory (affected version ranges are not specified in the data provided). Restrict management-interface access to trusted networks or a VPN rather than exposing it to the internet, and check controller hosts for unexpected file access. Because the flaw can expose underlying account credentials, consider rotating local administrator credentials for exposed controllers if compromise is suspected. | 10.0 | 28% |
| mass≈1M+ deployments (self-hosted controllers plus UniFi OS consoles running the Network Application) | ||
| CVE-2026-22558 | An Authenticated NoSQL Injection vulnerability found in UniFi Network Application could allow a malicious actor with authenticated access to the network to esca An Authenticated NoSQL Injection vulnerability found in UniFi Network Application could allow a malicious actor with authenticated access to the network to escalate privileges. NVD description · AI analysis pending | 7.7 | <1% | — | — |
Full article280 words · extracted from securityaffairs.com · click to collapse

Ubiquiti fixed two UniFi vulnerabilities, including a critical flaw that could let attackers take over user accounts.
Ubiquiti patched two vulnerabilities in its UniFi Network app, including a maximum-severity flaw that could enable account takeover. The software is widely used to manage UniFi networking devices like access points, switches, and gateways.
The Ubiquiti UniFi Network app is management software developed by Ubiquiti to control and monitor its UniFi networking devices.
It lets users configure, manage, and optimize hardware like Wi-Fi access points, switches, and gateways from a single dashboard. IT admins use it to set up networks, track performance, manage users, apply security settings, and troubleshoot issues, either locally or via the cloud.
The vendor addressed a maximum severity issue tracked as CVE-2026-22557 (CVSS score of 10.0), which affects UniFi Network application version 10.1.85 and earlier.
An attacker on the network could exploit a path traversal flaw in UniFi to access system files and potentially take over user accounts.
“A malicious actor with access to the network could exploit a Path Traversal vulnerability found in the UniFi Network Application to access files on the underlying system that could be manipulated to access an underlying account.” reads the advisory.
Versions 10.1.89 or later addressed the vulnerability.
The second issue addressed by Ubiquiti, tracked as CVE-2026-22558 (CVSS score of 7.7), resides in the UniFi Network app, attackers with low privileges can exploit it for privilege escalation.
“An Authenticated NoSQL Injection vulnerability found in UniFi Network Application could allow a malicious actor with authenticated access to the network to escalate privileges,” states the company.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, UniFi Network Application)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/189689/security/critical-ubiquiti-unifi-unifi-security-flaw-allows-potential-account-hijacking.html