Changeflow GovPing Data Privacy & Cybersecurity Ubiquiti UniFi Network Application Vulnerabilit...
Priority review Notice Amended Final

Ubiquiti UniFi Network Application Vulnerabilities Addressed

Favicon for www.csa.gov.sg CSA Alerts & Advisories (Singapore)
Published
Detected
Email

Summary

The Cyber Security Agency of Singapore (CSA) has issued an alert regarding multiple vulnerabilities in Ubiquiti UniFi Network Application. Users are advised to update to the latest version immediately to address potential account compromise and privilege escalation risks.

Published by CSA on csa.gov.sg . Detected, standardized, and enriched by GovPing. Review our methodology and editorial standards .

What changed

The Cyber Security Agency of Singapore (CSA) has issued an alert concerning multiple critical vulnerabilities (CVE-2026-22557 and CVE-2026-22558) affecting Ubiquiti UniFi Network Application versions 10.1.85 and earlier. CVE-2026-22557, a Path Traversal vulnerability with a CVSSv3.1 score of 10.0, could allow attackers to access system files and compromise accounts. CVE-2026-22558, an Authenticated NoSQL Injection vulnerability, could enable privilege escalation for authenticated users.

Users and administrators of affected Ubiquiti UniFi Network Application versions are strongly advised to update to the latest version immediately to mitigate these risks. Failure to update could result in unauthorized access, account compromise, and privilege escalation, impacting the security and integrity of their networks.

What to do next

  1. Update Ubiquiti UniFi Network Application to the latest version immediately.

Archived snapshot

Mar 23, 2026

GovPing captured this document from the original source. If the source has since changed or been removed, this is the text as it existed at that time.

Alerts

Multiple Vulnerabilities in Ubiquiti UniFi Network Application

23 March 2026

Ubiquiti has released software updates addressing multiple vulnerabilities in Ubiquiti UniFi Network Application. Users and administrators of affected products are advised to update to the latest version immediately.

Background

Ubiquiti has released software updates addressing multiple vulnerabilities (CVE-2026-22557 and CVE-2026-22558) in Ubiquiti UniFi Network Application.

Impact

Successful exploitation of the vulnerabilities could lead to the following:

  • CVE-2026-22557: Successful exploitation of the Path Traversal vulnerability could allow an attacker to access files in the system, leading to potential account compromise. The vulnerability has a Common Vulnerability Scoring System (CVSSv3.1) score of 10.0 out of 10.

  • CVE-2026-22558: Successful exploitation of the Authenticated NoSQL Injection vulnerability could allow an authenticated attacker to perform privilege escalation.
    Affected Products

The vulnerabilities affect UniFi Network Application versions 10.1.85 and earlier.

Recommendation

Users and administrators of affected product versions are advised to update to the latest version immediately.

References

https://community.ui.com/releases/Security-Advisory-Bulletin-062-062/c29719c0-405e-4d4a-8f26-e343e99f931b

https://nvd.nist.gov/vuln/detail/CVE-2026-22557

https://nvd.nist.gov/vuln/detail/CVE-2026-22558

https://www.bleepingcomputer.com/news/security/ubiquiti-warns-of-unifi-flaw-that-may-enable-account-takeover/

Back to top

Get daily alerts for CSA Alerts & Advisories (Singapore)

Daily digest delivered to your inbox.

Free. Unsubscribe anytime.

About this page

What is GovPing?

Every important government, regulator, and court update from around the world. One place. Real-time. Free. Our mission

What's from the agency?

Source document text, dates, docket IDs, and authority are extracted directly from CSA.

What's AI-generated?

The summary, classification, recommended actions, deadlines, and penalty information are AI-generated from the original text and may contain errors. Always verify against the source document.

Last updated

Classification

Agency
CSA
Published
March 23rd, 2026
Instrument
Notice
Legal weight
Non-binding
Stage
Final
Change scope
Substantive
Document ID
al-2026-025

Who this affects

Applies to
Technology companies
Industry sector
5112 Software & Technology
Activity scope
Network Security Software Updates
Geographic scope
Singapore SG

Taxonomy

Primary area
Cybersecurity
Operational domain
IT Security
Compliance frameworks
NIST CSF
Topics
Product Security Vulnerability Management

Get alerts for this source

We'll email you when CSA Alerts & Advisories (Singapore) publishes new changes.

Free. Unsubscribe anytime.

You're subscribed!