Critical Ubiquiti UniFi Vulnerability Requires Immediate Update (CVE-2026-22557)

Ubiquiti disclosed a CVSS 10.0 critical flaw in UniFi Network Application that allows account takeover without authentication. Update immediately.

Published 2026-03-20 by TechNet New England

Ubiquiti has disclosed two critical vulnerabilities in its UniFi Network Application that require immediate patching. The most severe, CVE-2026-22557, carries the maximum CVSS score of 10.0 and allows attackers to take over accounts without any authentication.

What's the Risk?

The vulnerability is a Path Traversal flaw that allows attackers with network access to:

No authentication, no user interaction, and no special conditions are required to exploit this remotely.

If your UniFi controller is exposed to the internet (even through port forwarding), this is an emergency.

The Two Vulnerabilities

CVESeverityCVSSTypeAuth Required?
CVE-2026-22557Critical10.0Path TraversalNo
CVE-2026-22558High7.7NoSQL InjectionYes

CVE-2026-22558 requires authentication but can be used for privilege escalation once an attacker has low-level access.

Affected Versions

UniFi Network Application version 10.1.85 and earlier are vulnerable.

This includes:

The Fix

Update to one of these patched versions immediately:

ProductFixed Version
UniFi Network Application (Official)10.1.89 or later
UniFi Network Application (RC)10.2.97 or later
UniFi Express (UX) Firmware4.0.13 or later

How to Update

For UDM/UDM-Pro/UDM-SE:

  1. Log into your UniFi Console
  2. Go to Settings → System → Updates
  3. Enable "Release Candidate" if you don't see the update
  4. Click Update

For Self-Hosted Controllers:

  1. Download the latest version from Ubiquiti Downloads
  2. Stop the UniFi service
  3. Install the update
  4. Restart the service

For Cloud Keys:

  1. Log into the Cloud Key
  2. Go to Settings → Updates
  3. Apply any available firmware and application updates

Immediate Mitigations (If You Can't Update Yet)

If you need time before updating:

How to Check Your Version

  1. Log into your UniFi Network Application
  2. Click the gear icon (Settings)
  3. Go to System
  4. Look for "Network Application Version"

If it shows 10.1.85 or lower, you're vulnerable.

Credit

The vulnerabilities were discovered by security researcher Garett Kopcha (@0x5t) and responsibly disclosed to Ubiquiti.

References

Need Help?

If you're running UniFi equipment and aren't sure whether you're affected or how to update safely, we can help. A quick review of your network setup can ensure you're protected against this and other vulnerabilities.