CVE-2026-22558: Ubiquiti Inc UniFi Network Application

High severity, CVSS 7.7. EPSS: 0.6% chance of exploitation in the next 30 days.

An Authenticated NoSQL Injection vulnerability found in UniFi Network Application could allow a malicious actor with authenticated access to the network to escalate privileges.

Affected products

  • Ubiquiti Inc UniFi Network Application: from 10.1, before 10.1.89 (fixed in 10.1.89); from 10.2, before 10.2.97 (fixed in 10.2.97); from 9, before 9.0.118 (fixed in 9.0.118)

Published 2026-03-19. Last modified 2026-06-17.