CVE-2026-22558Patch

MEDIUMCVSS 7.7 · HIGH

Exploitation observed; activity peaked at 6 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

An Authenticated NoSQL Injection vulnerability found in UniFi Network Application could allow a malicious actor with authenticated access to the network to escalate privileges.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-943

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 19 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 10 signals
  • Technical details provided in 14 signals
  • General: 6 classified signals
  • Disclosure: 3 classified signals
  • Peaked 5d ago at 6 mentions (2026-03-19); latest day: 3
  • 19 total mentions across 7 days

Deep dive

Activity timeline19 mentions / 7d
02356Mentions · 2026-03-18: 2Mentions · 2026-03-19: 6Mentions · 2026-03-20: 2Mentions · 2026-03-21: 2Mentions · 2026-03-23: 3Mentions · 2026-03-26: 1Mentions · 2026-06-08: 3Active Exploitation · 2026-03-18: 1Patch / Workaround · 2026-03-18: 1Patch / Workaround · 2026-03-19: 3Patch / Workaround · 2026-03-20: 2Patch / Workaround · 2026-03-21: 2Patch / Workaround · 2026-03-23: 1Patch / Workaround · 2026-03-26: 1Technical Details · 2026-03-18: 2Technical Details · 2026-03-19: 5Technical Details · 2026-03-20: 2Technical Details · 2026-03-21: 2Technical Details · 2026-03-23: 2Technical Details · 2026-03-26: 103-1803-1903-2003-2103-2303-2606-08
Signal classification4 categories
Patch
947.4%
General
631.6%
Disclosure
315.8%
Active Exploitation
15.3%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-03-182
Active Exploitation1Disclosure1
2026-03-196
Disclosure2General1Patch3
2026-03-202
Patch2
2026-03-212
Patch2
2026-03-233
General2Patch1
2026-03-261
Patch1
2026-06-083
General3
Full discourse19 posts
  • International Cyber Digest@IntCyberDigest
    Disclosure

    🚨‼️ CRITICAL: Ubiquiti UniFi Network Application vulnerabilities were just disclosed CVE-2026-22557 CVSS 10.0 Remote path traversal vulnerability allowing an attacker to access and manipulate files, leading to account takeover. No authentication required. CVE-2026-22558 — CVSS 7.7 Authenticated NoSQL Injection allowing privilege escalation.

    Post summary

    The text announces the disclosure of two new Ubiquiti UniFi vulnerabilities (CVE-2026-22557 and CVE-2026-22558), detailing their technical characteristics and impact, without offering proof of concept, exploit code, active exploitation evidence, or remediation steps.

    42334372.1K846308.0K
    99.6K followersView on X
  • Ezequiel Librandi@EzeLibrandi
    Patch

    🚨ATENCIÓN GORDOS UBIQUITI!!! Actualicen Unifi Network Application: se publicaron 2 vulnerabilidades, una de ellas CRÍTICA! - CVE-2026-22557 (10.0): Remote Path Traversal que permitiría a un atacante acceder y manipular archivos, e incluso comprometer cuentas sin autenticación. - CVE-2026-22558 (7.7): NoSQL Injection que permitiría escalar privilegios (requiere autenticación). Como mitigarlo? - Release (estable): actualizar a 10.1.89+ - Release Candidate: actualizar a 10.2.97+ - UniFi Express (UX): actualizar firmware a 4.0.13+ (incluye UniFi Network 9.0.118+)

    Post summary

    The post alerts about two critical CVEs affecting Ubiquiti Unifi, provides technical details of each vulnerability, and urges users to apply specific firmware updates to mitigate the risks.

    75022159128.6K
    1.8K followersView on X
  • ثامر الغالي@alghali
    Disclosure

    🚨‼️ تحذير أمني حرج: تم الكشف للتو عن ثغرات خطيرة في تطبيق الشبكات Ubiquiti UniFi Network! 🔴 CVE-2026-22557 (تقييم CVSS 10.0 - خطورة قصوى) ثغرة اختراق مسار عن بُعد (Remote Path Traversal) تسمح للمهاجم بالوصول للملفات وتعديلها، مما يؤدي للاستيلاء الكامل على الحساب (لا تتطلب أي مصادقة!). 🟠 CVE-2026-22558 (تقييم CVSS 7.7 - خطورة عالية) ثغرة حقن (NoSQL Injection) تتطلب مصادقة مسبقة، وتسمح للمهاجم برفع مستوى الصلاحيات. يرجى تحديث أنظمتكم فوراً لتجنب الاختراق! 🛡️💻

    Post summary

    The post announces two newly identified CVEs for Ubiquiti UniFi Network, providing technical details but no proof of concept, exploit code, or evidence of active exploitation.

    260524513.5K
    86.4K followersView on X
  • Günter Born@etguenni
    Patch

    Setzt jemand die Ubiquiti UniFi Network Application ein? Es gibt zwei Schwachstellen CVE-2026-22557 (CVSS 3.1 10.0, ermöglicht Kontenübernahme), CVE-2026-22558 (CVSS 3.1 7.7 ermöglicht Rechteerweiterung) - patchen. https://borncity.com/blog/2026/03/19/ubiquiti-unifi-network-application-schwachstellen-cve-2026-22557-cve-2026-22558/

    Post summary

    The post alerts to two Ubiquiti UniFi Network Application vulnerabilities (CVE‑2026‑22557 and CVE‑2026‑22558) with high CVSS scores, enabling account takeover and privilege escalation, and urges users to apply patches.

    01040448
    2.6K followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: CVE‑2026‑22557 (Critical) & CVE‑2026‑22558 (High) in #UniFi Network App could lead to full system compromise. More info in https://ccb.belgium.be/advisories/warning-cve-2026-22557-cve-2026-22558-unifi-network-app-could-lead-full-system #patch #patch #patch

    Post summary

    An advisory warns that CVE‑2026‑22557 and 22558 in the UniFi Network App could enable full system compromise and urges users to patch.

    01002293
    7.2K followersView on X
  • TheTechWorldPodcast@TheTechWorldPod
    Active Exploitation

    CRITICAL Ubiquiti UniFi Network Application Vulnerabilities Disclosed Security Advisory Bulletin 062 – Published: March 18, 2026 These vulnerabilities affect the UniFi Network Application (the controller software for managing UniFi networking devices). 1. CVE-2026-22557 – Remote Path Traversal (Critical – CVSS 10.0) - Discovered by: n00r3 (@izn0u) - Severity: Critical - CVSS v3.1 Base Score: 10.0 - Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H - Attack Vector: Network (remote, over the internet or local network) - Attack Complexity: Low - Privileges Required: None - User Interaction: None - Scope: Changed - Impact: High on Confidentiality, Integrity, and Availability - Description: A path traversal vulnerability allows a malicious actor with network access to exploit directory traversal sequences (e.g., ../ patterns) in affected endpoints. This enables arbitrary file access and manipulation on the underlying host operating system running the UniFi Network Application. Successful exploitation can lead to reading sensitive files (configuration, credentials, logs), writing malicious files, or modifying system files in ways that facilitate full account takeover, remote code execution, or persistent access. - Authentication Required: None (unauthenticated remote attack possible if the UniFi controller's web interface or API is exposed) - Affected Versions: - Official Release: UniFi Network Application Version 10.1.85 and earlier - Release Candidate: UniFi Network Application Version 10.2.93 and earlier - Status: Actively exploitable in the wild (high risk if controller is internet-facing or on an untrusted network) - Recommendation: Immediate patching required 2. CVE-2026-22558 – Authenticated NoSQL Injection (High – CVSS 7.7) - Discovered by: Garett Kopcha (@0x5t) - Severity: High - CVSS v3.1 Base Score: 7.7 (High) - Description: An authenticated NoSQL injection vulnerability exists in the UniFi Network Application. A malicious actor with valid credentials (e.g., a compromised low-privilege user account) can inject malicious payloads into NoSQL database queries. This allows privilege escalation, potentially granting administrative or root-level access within the application or on the host system, depending on the query context and database permissions. - Authentication Required: Yes (requires valid authenticated access to the UniFi Network Application) - Attack Vector: Network - Impact: Privilege escalation; could lead to full compromise of the controller, device management takeover, or lateral movement in the network - Affected Versions: Same as above (UniFi Network Application Version 10.1.85 and earlier / RC 10.2.93 and earlier) Mitigation / Recommended Actions (from official advisory): - Update immediately to the latest stable version of UniFi Network Application (Version 10.2.x or newer stable release that supersedes the affected versions – check the Ubiquiti release notes or http://community.ui.com for the exact patched build). - If your controller is internet-facing: Restrict access via firewall rules, VPN-only access, or place it behind a reverse proxy with strong authentication. - Monitor for unusual login attempts, file access anomalies, or unexpected privilege changes. - Apply network segmentation: Isolate the management VLAN/subnet from untrusted devices. - Reference: Official advisory – https://community.ui.com/releases/Security-Advisory-Bulletin-062-062/c29719c0-405e-4d4a-8f26-e343e99f931b Patch as soon as possible – especially CVE-2026-22557, which is unauthenticated and scores a full 10.0 CVSS.

    Post summary

    This advisory discloses two critical vulnerabilities in UniFi Network Application that are actively exploitable and urges immediate patching and network hardening.

    00101340
    697 followersView on X
  • iototsecnews@iototsecnews
    Patch

    Ubiquiti UniFi の脆弱性に CVE-2026-22557/22558 が FIX:深刻なパス・トラバーサルと NoSQLi https://iototsecnews.jp/2026/03/19/critical-ubiquiti-unifi-vulnerabilities-allow-attackers-to-seize-full-control-of-underlying-systems/ Ubiquiti の UniFi Network Application における 2 件の深刻な脆弱性、 CVE-2026-22557/CVE-2026-22558 について解説する記事です。1 つ目の脆弱性 CVE-2026-22557 の原因は、 アプリケーション内のファイルパス処理における不備 (パス・トラバーサル) にあります。 本来アクセスできる範囲を超えて、 OS 上の機密ファイルまで読み書きできてしまう状態にあります。 認証すら不要で、 ネットワーク経由でシステム全体の制御を奪われる恐れがあるため、 CVSS スコアは最高値の 10.0 と評価されています。 もう一つの脆弱性 CVE-2026-22558 の原因は、 データベース操作時の入力検証不足による NoSQL インジェクションです。 すでに低権限でログインしている攻撃者が、 悪意のあるクエリを注入することで、 管理権限へと昇格できてしまいます。インターネットから管理画面へのアクセスが可能になっている場合には、 きわめて高いリスクがあるため、 優先的なパッチ適用が必要とされています。 #CVE202622557 #CVE202622558 #Ubiquiti #UniFi #Vulnerability

    Post summary

    The article discloses two critical Ubiquiti UniFi vulnerabilities—CVE‑2026‑22557 and CVE‑2026‑22558—detailing their technical aspects and urging the application of vendor patches.

    01000234
    481 followersView on X
  • bigmacd@bigmacd16684
    Patch

    Ubiquiti fixed critical CVE-2026-22557, a path traversal flaw in UniFi Network App v10.1.85 & below allowing account takeover, also CVE-2026-22558, an authenticated NoSQL injection (CVSS 7.7). #CyberSecurity

    Post summary

    Ubiquiti released a patch for two critical vulnerabilities—a path traversal flaw leading to account takeover and an authenticated NoSQL injection—highlighting the update’s importance.

    1000011
    4 followersView on X
  • Dave@RideToFireStar
    General

    Yawn 🥱 2026 recap: UniFi OS: - CVE-2026-34908 - 10 - CVE-2026-34909 - 10 - CVE-2026-34910 - 10 - CVE-2026-33000 - 9.1 - CVE-2026-34911 - 7.7 UniFi Play Devices: - CVE-2026-22563 - 9.8 - CVE-2026-22562 - 9.8 - CVE-2026-22564 - 9.8 - CVE-2026-22566 - 7.5 - CVE-2026-22565 - 7.5 UniFi Network (Controller): - CVE-2026-22557 - 10 - CVE-2026-22558 - 7.7 - CVE-2026-22559 - 8.8 UniFi Protect: - CVE-2026-21633 - 8.8 - CVE-2026-21634 - 6.5 UniFi airMAX: - CVE-2026-21638 - 8.8 So much fail, and we're not even halfway through 2026. Lots of 10s and 9s. 🤡🩰

    Post summary

    A simple summary of numerous UniFi CVEs and their associated severity scores, with no additional context or actionable information.

    00000116
    1.2K followersView on X
  • Dave@RideToFireStar
    General

    Yawn 🥱 2026 recap: UniFi OS: - CVE-2026-34908 - 10 - CVE-2026-34909 - 10 - CVE-2026-34910 - 10 - CVE-2026-33000 - 9.1 - CVE-2026-34911 - 7.7 UniFi Play Devices: - CVE-2026-22563 - 9.8 - CVE-2026-22562 - 9.8 - CVE-2026-22564 - 9.8 - CVE-2026-22566 - 7.5 - CVE-2026-22565 - 7.5 UniFi Network (Controller): - CVE-2026-22557 - 10 - CVE-2026-22558 - 7.7 - CVE-2026-22559 - 8.8 UniFi Protect: - CVE-2026-21633 - 8.8 - CVE-2026-21634 - 6.5 UniFi airMAX: - CVE-2026-21638 - 8.8 So much fail, and we're not even halfway through 2026. Lots of 10s and 9s. 🤡🩰

    Post summary

    A short tweet lists several 2026 CVEs for various UniFi products with numeric scores, but offers no technical, exploit, or mitigation details.

    0000057
    1.2K followersView on X
  • Dave@RideToFireStar
    General

    Yawn 🥱 2026 recap: UniFi OS: - CVE-2026-34908 - 10 - CVE-2026-34909 - 10 - CVE-2026-34910 - 10 - CVE-2026-33000 - 9.1 - CVE-2026-34911 - 7.7 UniFi Play Devices: - CVE-2026-22563 - 9.8 - CVE-2026-22562 - 9.8 - CVE-2026-22564 - 9.8 - CVE-2026-22566 - 7.5 - CVE-2026-22565 - 7.5 UniFi Network (Controller): - CVE-2026-22557 - 10 - CVE-2026-22558 - 7.7 - CVE-2026-22559 - 8.8 UniFi Protect: - CVE-2026-21633 - 8.8 - CVE-2026-21634 - 6.5 UniFi airMAX: - CVE-2026-21638 - 8.8 So much fail, and we're not even halfway through 2026. Lots of 10s and 9s. 🤡🩰

    Post summary

    The post enumerates multiple high‑severity CVEs affecting various UniFi products without providing additional technical, exploitation, or mitigation details.

    00000110
    1.2K followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Ubiquiti ❗ CVE-2026-22558 ❗ CVE-2026-22557 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-ubiquiti/ https://t.co/vDrmiNQyhK

    Post summary

    The tweet announces two CVEs tied to Ubiquiti products and links to another site for details, but offers no technical specifics, PoC, patch information, or evidence of active exploitation.

    00000145
    6.6K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-22558 An Authenticated NoSQL Injection vulnerability found in UniFi Network Application could allow a malicious actor with authenticated access to the network to escalate p… https://www.cve.org/CVERecord?id=CVE-2026-22558

    Post summary

    The entry briefly announces an authenticated NoSQL injection vulnerability (CVE‑2026‑22558) in UniFi Network Application that could allow attackers with credentials to potentially escape or elevate privileges. No exploitation details, patches, or PoCs are provided.

    00000127
    56.8K followersView on X
  • FirstPassLab@FirstPassLab
    Patch

    Ubiquiti UniFi CVE-2026-22557: CVSS 10 — third max-severity flaw in 12 months. Full breakdown: → Unauthenticated path traversal → admin account takeover → Companion CVE-2026-22558: NoSQL injection for privilege escalation → Affects all UniFi Network Application versions ≤ 10.1.89 → No exploitation in wild yet — but Censys says exploit complexity is low → Pattern analysis: three CVSS 10.0 in one year = systemic architecture issues → Management plane isolation guide (applies to UniFi, Cisco FMC, and every controller) https://firstpasslab.com/blog/2026-03-21-ubiquiti-unifi-cve-2026-22557-account-takeover-management-security/?utm_source=x&utm_medium=social&utm_campaign=ubiquiti-unifi-cve-2026-22557-account-takeover-management-security #Ubiquiti #UniFi #CVE202622557 #NetworkSecurity #PatchNow #CCIE

    Post summary

    The post announces a high‑severity (CVSS 10) path traversal flaw in Ubiquiti UniFi (CVE‑2026‑22557), notes no wild exploitation yet, and promotes a management plane isolation guide as a mitigation.

    0000082
    10 followersView on X
  • Sheila Reyes ⚓@SheilaReyesG
    Patch

    Ubiquiti publicó un advisory sobre UniFi Network con dos vulnerabilidades que vale la pena revisar. Una de ellas es crítica (CVE-2026-22557) y permite acceder y manipular archivos sin autenticación. La otra (CVE-2026-22558) permite escalar privilegios una vez que alguien ya está dentro del sistema. En pocas palabras: no necesitas credenciales para empezar… y si ya tienes acceso, puedes ir más lejos de lo que deberías. Y aquí es donde realmente está el punto importante. Este tipo de fallas nos recuerdan algo que vemos todo el tiempo en ciberseguridad: el problema no siempre es cómo entran… sino lo que pueden hacer una vez adentro. Por eso, sí, actualizar es urgente. Pero también lo es revisar accesos, privilegios y configuraciones dentro de la red. Porque al final, la seguridad no se trata solo de cerrar la puerta… sino de controlar qué pasa si alguien logra cruzarla. https://community.ui.com/releases/Security-Advisory-Bulletin-062-062/c29719c0-405e-4d4a-8f26-e343e99f931b

    Post summary

    Ubiquiti issued a UniFi Network advisory for CVE‑2026‑22557 and CVE‑2026‑22558, which provide unauthenticated file access and privilege escalation respectively; the advisory urges users to update promptly, though no PoC, exploit code, or active exploitation is reported.

    0000093
    90 followersView on X
  • ‏ᗩTTᗩᑕK@INFJ_100
    Patch

    🚨 تنبيه أمني تقني هام : ثغرات حرجة في أنظمة Ubiquiti UniFi 🚨 على جميع مسؤولي الشبكات ومستخدمي أجهزة UniFi بضرورة التحديث الفوري حيث تم الكشف عن ثغرتين أمنيتين تتطلبان إجراءً تقنياً عاجلاً: 🛡️ 🔴 1. الثغرة الأولى (CVE-2026-22557) 🔻مستوى الخطورة: 10/10 (حرجة جداً) 🔥 🔻الوصف: تسمح للمهاجم بالوصول إلى ملفات النظام وتعديلها عن بُعد والسيطرة الكاملة على الحساب بدون الحاجة لأي بيانات دخول أو مصادقة 🚫🔑 🟠 2. الثغرة الثانية (CVE-2026-22558) 🔻مستوى الخطورة: 7.7 (عالية) ⚡ 🔻الوصف: ثغرة من نوع (NoSQL Injection) تتيح للمستخدمين ذوي الصلاحيات المحدودة رفع مستوى صلاحياتهم بشكل غير قانوني والوصول لبيانات حساسة 📑⚠️ ✅ الإجراء المطلوب: يرجى تحديث تطبيق UniFi Network وكافة الأنظمة المرتبطة إلى أحدث إصدار متاح فوراً لسد هذه الثغرات وتأمين بيئة العمل من أي محاولات اختراق 💻 #الأمن_السيبراني #CyberSecurity

    Post summary

    The tweet alerts Ubiquiti UniFi administrators to two severe vulnerabilities (CVE‑2026‑22557 and CVE‑2026‑22558) and urges immediate software updates to mitigate potential remote compromise and privilege escalation.

    00000105
    196 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-22558 Authenticated NoSQL Injection in UniFi Network Application 10.1.85 and Earlier Enables Privilege Escalation https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-22558

    Post summary

    The post discloses an authenticated NoSQL injection in UniFi Network Application 10.1.85 and earlier that can lead to privilege escalation; it provides technical details but no PoC, exploit code, active exploitation report, or patch information.

    0000051
    4.0K followersView on X
  • 0x5t@0x55t
    General

    was pretty fun looking for - CVE-2026-22558 🚀

    Post summary

    The text merely references CVE-2026-22558 without providing any actionable or technical details.

    0000066
    18 followersView on X
  • Grok@grok
    Patch

    For CVE-2026-22557 (CVSS 10.0 path traversal): Network access to UniFi Network app (AV:N, no auth/PR:N/UI:N required). Exploits file access on underlying system → account takeover. For CVE-2026-22558 (CVSS 7.7 NoSQL injection): Authenticated network access (PR:L). Allows privilege escalation. Affected: UniFi Network app ≤10.1.85 / ≤10.2.93 RC / UX ≤9.0.114. Fix: Update to 10.1.89+ / 10.2.97+ / UX fw 4.0.13+.

    Post summary

    The notice lists two high‑severity CVEs for UniFi Network, provides technical details and affected versions, and supplies specific patch versions to mitigate the risks.

    00000384
    8.5M followersView on X

Explore more