Summary
| Parameter | Value |
|---|---|
| CVE ID | CVE-2026-22557 |
| Alert Source | Ubiquiti Security Advisory Bulletin 056 |
| CVE Publication Year | 2026 |
| Date Published | 2026-03-18 |
| Vendor | Ubiquiti |
| Product | UniFi Network Application |
| CVSS Score | 10.0 (Critical) |
| Vulnerability Type | Path Traversal (CWE-22) |
| Authentication | Not required |
| CISA KEV | No |
| Ransomware | Not confirmed |
Vulnerability Description
CVE-2026-22557 is a Path Traversal vulnerability in the UniFi Network Application that allows an unauthenticated attacker with network access to:
- Read and manipulate files on the host operating system
- Take over administrator accounts (account takeover)
- Gain full control over the device and managed network infrastructure
The vulnerability received the maximum CVSS score of 10.0, indicating the highest possible threat level.
Affected Products and Versions
| Product | Vulnerable Versions | Fixed Version |
|---|---|---|
| UniFi Network Application (Official) | <= 10.1.85 | 10.1.89 |
| UniFi Network Application (RC) | <= 10.2.93 | 10.2.97 |
| UniFi Express (UX) firmware | <= 9.0.114 | 4.0.13 (includes UNA 9.0.118+) |
Affected devices include Dream Machine, Dream Machine Pro, Dream Router, and all self-hosted UniFi Network Application installations.
Required Actions
- Immediately update UniFi Network Application to version 10.1.89 or later
- UniFi Express: update firmware to 4.0.13
- If immediate patching is not possible:
- Restrict network access to the UniFi management interface (firewall/ACL)
- Monitor logs for unusual HTTP requests to the UniFi application
- Consider temporarily disabling external access to the management panel
Related Vulnerabilities
Alongside CVE-2026-22557, Ubiquiti also patched a second vulnerability:
- CVE-2026-22558 - NoSQL Injection (CVSS 7.7) enabling privilege escalation. This vulnerability requires authentication, but when chained with CVE-2026-22557, it creates an attack chain allowing full system compromise.
Sources
Need help securing your systems? nFlo team offers vulnerability management and 24/7 SOC services. Contact us.
