CVE-2026-22557: Ubiquiti Inc UniFi Network Application

Critical severity, CVSS 10.0. EPSS: 28.1% chance of exploitation in the next 30 days.

A malicious actor with access to the network could exploit a Path Traversal vulnerability found in the UniFi Network Application to access files on the underlying system that could be manipulated to access an underlying account.

Affected products

  • Ubiquiti Inc UniFi Network Application: from 10.1, before 10.1.89 (fixed in 10.1.89); from 10.2, before 10.2.97 (fixed in 10.2.97); from 9, before 9.0.118 (fixed in 9.0.118)

Published 2026-03-19. Last modified 2026-06-17.