Skip to content
Security Alerts

CVE-2026-22558: Ubiquiti UniFi Network NoSQL Injection Vulnerability (CVSS 7.7)

NoSQL Injection vulnerability in Ubiquiti UniFi Network Application (CVSS 7.7) enables authenticated attackers to escalate privileges. When chained with CVE-2026-22557 (CVSS 10.0), it creates an attack chain leading to full system compromise.

Summary

ParameterValue
CVE IDCVE-2026-22558
Alert SourceUbiquiti Security Advisory Bulletin 056
CVE Publication Year2026
Date Published2026-03-18
VendorUbiquiti
ProductUniFi Network Application
CVSS Score7.7 (High)
Vulnerability TypeNoSQL Injection (CWE-943)
AuthenticationRequired
CISA KEVNo
RansomwareNot confirmed

Vulnerability Description

CVE-2026-22558 is a NoSQL Injection vulnerability in the UniFi Network Application that allows an authenticated attacker with network access to escalate their privileges within the application.

Ubiquiti has not disclosed details about the exact scope of privilege escalation.

Attack Chain with CVE-2026-22557

When combined with the critical CVE-2026-22557 (Path Traversal, CVSS 10.0), a dangerous attack chain emerges:

  1. CVE-2026-22557: Unauthenticated file access → account takeover
  2. CVE-2026-22558: Privilege escalation of compromised account → full control

Affected Products and Versions

ProductVulnerable VersionsFixed Version
UniFi Network Application (Official)<= 10.1.8510.1.89
UniFi Network Application (RC)<= 10.2.9310.2.97
UniFi Express (UX) firmware<= 9.0.1144.0.13

Required Actions

  1. Update UniFi Network Application to version 10.1.89 or later
  2. UniFi Express: update firmware to 4.0.13
  3. Review user accounts in UniFi for unauthorized privilege changes

Sources


Need help securing your systems? nFlo team offers vulnerability management and 24/7 SOC services. Contact us.

How can nFlo help?

If your organization uses products affected by this vulnerability, contact us. We can help with:

  • Verifying whether your systems are at risk
  • Implementing patches and risk mitigation
  • Monitoring for exploitation attempts in your environment

Useful resources:

Learn More

Share:

Talk to an expert

Have questions about this topic? Get in touch with our specialist.

Sales Representative
Grzegorz Gnych

Grzegorz Gnych

Sales Representative

Response within 24 hours
Free consultation
Individual approach

Providing your phone number will speed up contact.

Want to Reduce IT Risk and Costs?

Book a free consultation - we respond within 24h

Response in 24h Free quote No obligations

Or download free guide:

Download NIS2 Checklist