
Ubiquiti has released fixes for a pair of security issues in the UniFi Network Application. One of these flaws is critical and could allow unauthorized individuals to gain control of user accounts.
The UniFi Network Application (also known as the UniFi Controller) is a software tool used to configure, manage, and optimize Ubiquiti UniFi networking equipment, such as wireless access points, network switches, and gateways.
The company states that it “Combines powerful gateways with scalable WiFi and switching, offering real-time traffic overviews, visual network layouts, and optimization suggestions,” and recommends using a UniFi Cloud Gateway for deployment instead of a server or laptop.
The high-severity vulnerability, identified as CVE-2026-22557, affects UniFi Network Application version 10.1.85 and earlier, and has been resolved in version 10.1.89 and later.
By successfully exploiting this vulnerability, attackers without proper authorization can leverage a path traversal flaw to access sensitive files on the affected devices and potentially compromise user accounts through uncomplicated attacks that do not require any user interaction.
According to a security bulletin released on Wednesday, “An attacker with network access could exploit a Path Traversal vulnerability in the UniFi Network Application to access system files, which could then be manipulated to gain access to accounts.”
Ubiquiti also fixed a separate vulnerability in the UniFi Network app that could be exploited by attackers with minimal permissions to elevate their privileges.
The company further noted that an “Authenticated NoSQL Injection vulnerability in the UniFi Network Application could enable a malicious actor with authenticated access to escalate their privileges.”
Ubiquiti products have increasingly become targets for both government-sponsored hacking groups and cybercriminals, who compromise them to build botnets to conceal their malicious activities.
As an example, in February 2024, the FBI took down a botnet composed of compromised Ubiquiti Edge OS routers that were being used by Russia’s GRU to route malicious traffic in attacks targeting the U.S. and its allies.
#accounts #bug #flaw #hackers #hijack #may #news #severity #top #unifi #with — News
© Bulletproof Servers. All rights reserved.