• News/
  • https://www.bleepingcomputer.com/news/security/ubiquiti-warns-of-unifi-flaw-that-may-enable-account-takeover/

Max severity Ubiquiti UniFi flaw may allow account takeover

BleepingComputer
·
Sergiu Gatlan
·
Published Mar 19, 2026
·
Updated

Ubiquiti has patched two vulnerabilities in the UniFi Network Application, including a maximum-severity flaw that may allow attackers to take over user accounts. The UniFi Network app (also known as the UniFi Controller) is management software that helps configure, monitor, and optimize Ubiquiti UniFi networking hardware, such as access points, switches, and gateways. "Combines powerful internet gateways with scalable WiFi and switching. Provides real-time traffic dashboards, visual topology maps, and optimization tips," the networking device manufacturer says. "The preferred way to deploy UniFi Network is on a UniFi Cloud Gateway, rather than on a server, laptop, or other self-hosted environment." Tracked as CVE-2026-22557, the security flaw impacts UniFi Network application version 10.1.85 and earlier and is addressed in versions 10.1.89 or later. Successful exploitation enables threat actors without privileges to exploit a path traversal vulnerability to access files on the targeted devices and potentially hijack user accounts in low-complexity attacks that don't require user interaction. "A malicious actor with access to the network could exploit a Path Traversal vulnerability found in the UniFi Network Application to access files on the underlying system that could be manipulated to access an underlying account," the company said in an advisory. Censys is currently tracking nearly 29,000 Internet-exposed UniFi Network endpoints, most of them (just over 28,000 IP address...

Read full article

Affected Software

2 affected components
Ubiquiti UniFi Network Application<=10.1.85
Ubiquiti UniFi Network Application
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What vulnerabilities were reported in the Ubiquiti UniFi Network Application?

Two vulnerabilities were reported, including a maximum-severity flaw that may enable account takeover.

2

What is the potential impact of the UniFi Network Application flaw?

The flaw could allow attackers to gain unauthorized access to user accounts.

3

Which version of Ubiquiti's software is affected by the flaw?

The vulnerability affects the Ubiquiti UniFi Network Application up to version 10.1.85.

4

Has Ubiquiti released a fix for the vulnerabilities?

Yes, Ubiquiti has released patches addressing the vulnerabilities in the UniFi Network Application.

5

What is the purpose of the UniFi Network Application?

The UniFi Network Application, also known as the UniFi Controller, is management software for Ubiquiti's networking products.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203