Ubiquiti UniFi Network Application Vulnerabilities Addressed
Summary
The Cyber Security Agency of Singapore (CSA) has issued an alert regarding multiple vulnerabilities in Ubiquiti UniFi Network Application. Users are advised to update to the latest version immediately to address potential account compromise and privilege escalation risks.
What changed
The Cyber Security Agency of Singapore (CSA) has issued an alert concerning multiple critical vulnerabilities (CVE-2026-22557 and CVE-2026-22558) affecting Ubiquiti UniFi Network Application versions 10.1.85 and earlier. CVE-2026-22557, a Path Traversal vulnerability with a CVSSv3.1 score of 10.0, could allow attackers to access system files and compromise accounts. CVE-2026-22558, an Authenticated NoSQL Injection vulnerability, could enable privilege escalation for authenticated users.
Users and administrators of affected Ubiquiti UniFi Network Application versions are strongly advised to update to the latest version immediately to mitigate these risks. Failure to update could result in unauthorized access, account compromise, and privilege escalation, impacting the security and integrity of their networks.
What to do next
- Update Ubiquiti UniFi Network Application to the latest version immediately.
Source document (simplified)
Alerts
Multiple Vulnerabilities in Ubiquiti UniFi Network Application
23 March 2026
Ubiquiti has released software updates addressing multiple vulnerabilities in Ubiquiti UniFi Network Application. Users and administrators of affected products are advised to update to the latest version immediately.
Background
Ubiquiti has released software updates addressing multiple vulnerabilities (CVE-2026-22557 and CVE-2026-22558) in Ubiquiti UniFi Network Application.
Impact
Successful exploitation of the vulnerabilities could lead to the following:
CVE-2026-22557: Successful exploitation of the Path Traversal vulnerability could allow an attacker to access files in the system, leading to potential account compromise. The vulnerability has a Common Vulnerability Scoring System (CVSSv3.1) score of 10.0 out of 10.
CVE-2026-22558: Successful exploitation of the Authenticated NoSQL Injection vulnerability could allow an authenticated attacker to perform privilege escalation.
Affected Products
The vulnerabilities affect UniFi Network Application versions 10.1.85 and earlier.
Recommendation
Users and administrators of affected product versions are advised to update to the latest version immediately.
References
https://nvd.nist.gov/vuln/detail/CVE-2026-22557
Related changes
Source
Classification
Who this affects
Taxonomy
Browse Categories
Get Data Privacy & Cybersecurity alerts
Weekly digest. AI-summarized, no noise.
Free. Unsubscribe anytime.
Get alerts for this source
We'll email you when CSA Alerts & Advisories (Singapore) publishes new changes.