Max severity Ubiquiti UniFi flaw may allow account takeover
ID: d7ad9ba2-8cda-5044-afca-aa59830f9059
STIX ID: report--d7ad9ba2-8cda-5044-afca-aa59830f9059
Feed Name: Bleeping Computer
Ubiquiti patched two serious vulnerabilities in the UniFi Network Application: CVE-2026-22557, a path traversal flaw in versions 10.1.85 and earlier that can allow attackers to access files and potentially hijack user accounts, and an authenticated NoSQL injection that can be used for privilege escalation; both are fixed in 10.1.89 or later. The advisory notes the low complexity and lack of required user interaction for exploitation and reminds readers that Ubiquiti products have been previously targeted by state-backed groups and cybercriminals.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
