Changeflow GovPing Data Privacy & Cybersecurity Ubiquiti UniFi Network Application Vulnerabilit...
Priority review Notice Amended Final

Ubiquiti UniFi Network Application Vulnerabilities Addressed

Favicon for www.csa.gov.sg CSA Alerts & Advisories (Singapore)
Published March 23rd, 2026
Detected March 23rd, 2026
Email

Summary

The Cyber Security Agency of Singapore (CSA) has issued an alert regarding multiple vulnerabilities in Ubiquiti UniFi Network Application. Users are advised to update to the latest version immediately to address potential account compromise and privilege escalation risks.

What changed

The Cyber Security Agency of Singapore (CSA) has issued an alert concerning multiple critical vulnerabilities (CVE-2026-22557 and CVE-2026-22558) affecting Ubiquiti UniFi Network Application versions 10.1.85 and earlier. CVE-2026-22557, a Path Traversal vulnerability with a CVSSv3.1 score of 10.0, could allow attackers to access system files and compromise accounts. CVE-2026-22558, an Authenticated NoSQL Injection vulnerability, could enable privilege escalation for authenticated users.

Users and administrators of affected Ubiquiti UniFi Network Application versions are strongly advised to update to the latest version immediately to mitigate these risks. Failure to update could result in unauthorized access, account compromise, and privilege escalation, impacting the security and integrity of their networks.

What to do next

  1. Update Ubiquiti UniFi Network Application to the latest version immediately.

Source document (simplified)

Alerts

Multiple Vulnerabilities in Ubiquiti UniFi Network Application

23 March 2026

Ubiquiti has released software updates addressing multiple vulnerabilities in Ubiquiti UniFi Network Application. Users and administrators of affected products are advised to update to the latest version immediately.

Background

Ubiquiti has released software updates addressing multiple vulnerabilities (CVE-2026-22557 and CVE-2026-22558) in Ubiquiti UniFi Network Application.

Impact

Successful exploitation of the vulnerabilities could lead to the following:

  • CVE-2026-22557: Successful exploitation of the Path Traversal vulnerability could allow an attacker to access files in the system, leading to potential account compromise. The vulnerability has a Common Vulnerability Scoring System (CVSSv3.1) score of 10.0 out of 10.

  • CVE-2026-22558: Successful exploitation of the Authenticated NoSQL Injection vulnerability could allow an authenticated attacker to perform privilege escalation.
    Affected Products

The vulnerabilities affect UniFi Network Application versions 10.1.85 and earlier.

Recommendation

Users and administrators of affected product versions are advised to update to the latest version immediately.

References

https://community.ui.com/releases/Security-Advisory-Bulletin-062-062/c29719c0-405e-4d4a-8f26-e343e99f931b

https://nvd.nist.gov/vuln/detail/CVE-2026-22557

https://nvd.nist.gov/vuln/detail/CVE-2026-22558

https://www.bleepingcomputer.com/news/security/ubiquiti-warns-of-unifi-flaw-that-may-enable-account-takeover/

Back to top

Source

Analysis generated by AI. Source diff and links are from the original.

Classification

Agency
CSA
Published
March 23rd, 2026
Instrument
Notice
Legal weight
Non-binding
Stage
Final
Change scope
Substantive
Document ID
al-2026-025

Who this affects

Applies to
Technology companies
Industry sector
5112 Software & Technology
Activity scope
Network Security Software Updates
Geographic scope
Singapore SG

Taxonomy

Primary area
Cybersecurity
Operational domain
IT Security
Compliance frameworks
NIST CSF
Topics
Product Security Vulnerability Management

Get Data Privacy & Cybersecurity alerts

Weekly digest. AI-summarized, no noise.

Free. Unsubscribe anytime.

Get alerts for this source

We'll email you when CSA Alerts & Advisories (Singapore) publishes new changes.

Free. Unsubscribe anytime.