Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Microsoft Defender Driver Vulnerability Lets Attackers Disable Security
August 20, 2026
AWS Guide: Prevent AI Agents From Accessing Unauthorized Data
August 20, 2026
Critical Rust Vulnerabilities Expose 244M Downloads to Malware
August 20, 2026
Home/CyberSecurity News/Critical Ubiquiti UniFi Vulnerabilities Let Attackers Seize Control
CyberSecurity News

Critical Ubiquiti UniFi Vulnerabilities Let Attackers Seize Control

Key Takeaways Ubiquiti has disclosed two critical and high-severity vulnerabilities affecting its UniFi Network Application. The most severe flaw, CVE-2026-22557, is a path traversal vulnerability...

Emy Elsamnoudy
Emy Elsamnoudy
March 19, 2026 3 Min Read
64 0

Key Takeaways

  • Ubiquiti has disclosed two critical and high-severity vulnerabilities affecting its UniFi Network Application.
  • The most severe flaw, CVE-2026-22557, is a path traversal vulnerability with a CVSS score of 10.0, allowing unauthenticated attackers to gain full system control.
  • The second vulnerability, CVE-2026-22558, is an authenticated NoSQL injection flaw rated 7.7, enabling privilege escalation.
  • Organizations using affected versions of UniFi Network Application, UniFi Network App (Release Candidate), and UniFi Express (UX) must apply patches immediately.
  • Ubiquiti has released security updates to address both issues.

Critical Vulnerabilities Expose Ubiquiti UniFi Systems to Full Takeover

Ubiquiti has issued an urgent security advisory concerning two significant vulnerabilities within its widely deployed UniFi Network Application. One of these flaws, rated with the maximum possible severity, could allow remote, unauthenticated attackers to completely compromise underlying systems, prompting an immediate call for all affected organizations to update their installations.

Table Of Content

  • Key Takeaways
  • Critical Vulnerabilities Expose Ubiquiti UniFi Systems to Full Takeover
  • CVE-2026-22557: Unauthenticated Path Traversal Leads to System Compromise
  • CVE-2026-22558: Authenticated NoSQL Injection Elevates Privileges
  • What You Should Do

CVE-2026-22557: Unauthenticated Path Traversal Leads to System Compromise

The more critical of the two security defects is identified as CVE-2026-22557, a path traversal vulnerability that has been assigned a CVSS v3.1 Base Score of 10.0. This perfect score signifies the utmost severity.

The exploit vector, designated AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H, confirms that an attacker can exploit this vulnerability remotely without needing any prior authentication, user interaction, or specific environmental conditions.

Exploiting this flaw grants a malicious actor with network access the ability to bypass directory restrictions within the UniFi Network Application. This allows them to access and manipulate sensitive files located on the host operating system. Such manipulation could lead to unauthorized access to system accounts, ultimately providing the attacker with full administrative control over the compromised host.

Security researcher n00r3, known as @izn0u, is credited with discovering and reporting this critical vulnerability.

CVE-2026-22558: Authenticated NoSQL Injection Elevates Privileges

The second vulnerability, CVE-2026-22558, is an authenticated NoSQL Injection flaw. It holds a CVSS v3.1 score of 7.7, categorizing it as high severity. While this vulnerability necessitates prior authentication (PR:L), its impact is significant due to a changed scope (S:C) and high confidentiality impact. This makes it a potent tool for attackers who have already acquired low-level credentials to escalate their privileges.

By injecting malicious NoSQL queries through the application interface, an authenticated attacker could bypass their authorized access levels. This could potentially lead to the compromise of sensitive network configuration data and internal account structures. Garett Kopcha, identified as @0x5t, discovered this vulnerability.

The following table outlines the affected product versions:

Product Affected Version
UniFi Network App (Official) 10.1.85 and earlier
UniFi Network App (Release Candidate) 10.2.93 and earlier
UniFi Express (UX) Network App 9.0.114 and earlier

What You Should Do

Ubiquiti has released patched versions that address both vulnerabilities. Administrators are strongly advised to apply these updates without delay:

  • For Official Release Users: Upgrade to UniFi Network Application Version 10.1.89 or a later version.
  • For Release Candidate Users: Upgrade to UniFi Network Application Version 10.2.97 or a later version.
  • For UniFi Express (UX) Users: Update the device firmware to Version 4.0.13 or later, which includes Network Application Version 9.0.118 or later.

Given the critical nature of CVE-2026-22557, particularly its perfect CVSS score and unauthenticated remote exploitability, organizations should also implement additional defensive measures. These include network segmentation and strict firewall rules to limit the exposure of the UniFi Network Application management interface.

Ubiquiti customers operating any of the affected versions in environments accessible from the internet face an exceptionally high risk and should treat this patching requirement as an emergency.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchSecurityVulnerability

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

New Vibe-Coded Malware Campaign Leverages Fake Tools, CDNs, and File Hosts

Next Post

CISA Urges Patching Microsoft Intune After Stryker Breach

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Fake CAPTCHA Installs Malware That Kills 145 Security Processes
August 20, 2026
New Android Malware Steals Banking PINs and Relays Data Through Infected Phones
August 20, 2026
Critical Microsoft 365 Flaw Lets Attackers Bypass MFA, Hijack Mailboxes
August 20, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us