logo

Critical Ubiquiti UniFi UniFi security flaw allows potential account hijacking

ID: e1e06757-d7ce-5253-8e8f-316baebb9ff4

STIX ID: report--e1e06757-d7ce-5253-8e8f-316baebb9ff4

Feed Name: Security Affairs

Threat Score
75/100

Date Published: 2026-03-19

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Ubiquiti patched two vulnerabilities in the UniFi Network application: a critical path traversal (CVE-2026-22557, CVSS 10.0) that could allow an attacker on the network to access system files and take over user accounts, and an authenticated NoSQL injection (CVE-2026-22558, CVSS 7.7) that could lead to privilege escalation; upgrades to version 10.1.89 or later address the issues.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.