logo

Total Takeover: Critical 10.0 CVSS Path Traversal Flaw Hits Ubiquiti UniFi Networks

ID: 042eaebc-5257-51b1-b92b-c4ecc9575b9b

STIX ID: report--042eaebc-5257-51b1-b92b-c4ecc9575b9b

Feed Name: securityonline.info

Threat Score
80/100

Date Published: 2026-03-19

Date Updated: 2026-04-23

Author: Ddos

...
...

Ubiquiti issued an urgent advisory for two vulnerabilities in the UniFi Network Application: a Critical unauthenticated Path Traversal (CVE-2026-22557, CVSS 10.0) enabling potential full system compromise, and a High authenticated NoSQL Injection (CVE-2026-22558, CVSS 7.7) that can escalate privileges. The advisory lists affected release branches (Official Release, Release Candidate, UniFi Express UX) and directs users to update to Official 10.1.89+, RC 10.2.97+, or UX firmware 4.0.13 (App 9.0.118) to remediate the issues.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.