Ubiquiti has patched two vulnerabilities in the UniFi Network Application, including a maximum-severity flaw that may allow attackers to take over user accounts. The UniFi Network app (also known as the UniFi Controller) is management software that helps configure, monitor, and optimize Ubiquiti UniFi networking hardware, such as access points, switches, and gateways. "Combines powerful internet gateways with scalable WiFi and switching. Provides real-time traffic dashboards, visual topology maps, and optimization tips," the networking device manufacturer says. "The preferred way to deploy UniFi Network is on a UniFi Cloud Gateway, rather than on a server, laptop, or other self-hosted environment." Tracked as CVE-2026-22557, the security flaw impacts UniFi Network application version 10.1.85 and earlier and is addressed in versions 10.1.89 or later. Successful exploitation enables threat actors without privileges to exploit a path traversal vulnerability to access files on the targeted devices and potentially hijack user accounts in low-complexity attacks that don't require user interaction. "A malicious actor with access to the network could exploit a Path Traversal vulnerability found in the UniFi Network Application to access files on the underlying system that could be manipulated to access an underlying account," the company said in an advisory. Censys is currently tracking nearly 29,000 Internet-exposed UniFi Network endpoints, most of them (just over 28,000 IP address...
Max severity Ubiquiti UniFi flaw may allow account takeover
BleepingComputer
·Sergiu Gatlan
·Published Mar 19, 2026
·Updated
Affected Software
2 affected components
Ubiquiti UniFi Network Application<=10.1.85
Ubiquiti UniFi Network Application
Frequently Asked Questions
1
What vulnerabilities were reported in the Ubiquiti UniFi Network Application?
Two vulnerabilities were reported, including a maximum-severity flaw that may enable account takeover.
2
What is the potential impact of the UniFi Network Application flaw?
The flaw could allow attackers to gain unauthorized access to user accounts.
3
Which version of Ubiquiti's software is affected by the flaw?
The vulnerability affects the Ubiquiti UniFi Network Application up to version 10.1.85.
4
Has Ubiquiti released a fix for the vulnerabilities?
Yes, Ubiquiti has released patches addressing the vulnerabilities in the UniFi Network Application.
5
What is the purpose of the UniFi Network Application?
The UniFi Network Application, also known as the UniFi Controller, is management software for Ubiquiti's networking products.