CVE-2026-22558: Ubiquiti Inc UniFi Network Application
High severity, CVSS 7.7. EPSS: 0.6% chance of exploitation in the next 30 days.
An Authenticated NoSQL Injection vulnerability found in UniFi Network Application could allow a malicious actor with authenticated access to the network to escalate privileges.
Affected products
- Ubiquiti Inc UniFi Network Application: from 10.1, before 10.1.89 (fixed in 10.1.89); from 10.2, before 10.2.97 (fixed in 10.2.97); from 9, before 9.0.118 (fixed in 9.0.118)
Published 2026-03-19. Last modified 2026-06-17.