CVE-2026-22558
Ubiquiti UniFi vulnerability analysis and mitigation

Overview

CVE-2026-22558 is an authenticated NoSQL injection vulnerability in Ubiquiti's UniFi Network Application that allows a malicious actor with authenticated network access to escalate privileges and access sensitive data. It was published on March 19, 2026, and assigned by HackerOne. Affected versions are UniFi Network Application prior to 9.0.118, 10.1.89, and 10.2.97 (Ubiquiti Advisory, ENISA EUVD). The vulnerability carries a CVSS v3.1 base score of 7.7 (High) with a changed scope, reflecting its potential to impact resources beyond the vulnerable component (Feedly).

Technical details

The vulnerability is classified as CWE-943 (Improper Neutralization of Special Elements in Data Query Logic), specifically a NoSQL injection flaw (CAPEC-676) in the UniFi Network Application's backend query handling (Feedly). An authenticated attacker can craft malicious query inputs that bypass intended data access controls in the MongoDB-backed application, enabling privilege escalation. The attack requires only low privileges, no user interaction, and is exploitable remotely over the network (ENISA EUVD). A technical write-up and weaponization analysis has been published by Bishop Fox covering this and the related CVE-2026-22557 (Bishop Fox).

Impact

Successful exploitation allows an authenticated attacker to escalate privileges within the UniFi Network Application, gaining unauthorized access to sensitive network configuration data and potentially other users' account information. The CVSS scoring reflects a high confidentiality impact with a changed scope, meaning the attacker can access data beyond their authorized boundary — including network topology, device credentials, and administrative settings. Integrity and availability are not directly impacted by this vulnerability, but privilege escalation could serve as a stepping stone for further compromise of managed network infrastructure (Feedly, ENISA EUVD).

Exploitability

As of the time of reporting, there is no public proof-of-concept exploit specifically for CVE-2026-22558, and no confirmed in-the-wild exploitation has been observed (Feedly). The EPSS score is approximately 0.026%, indicating a low current probability of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Bishop Fox has published a blog post analyzing and weaponizing the related CVE-2026-22557 (a critical path traversal flaw disclosed simultaneously), which may lower the barrier for chained exploitation (Bishop Fox).

Exploitation steps

  1. Reconnaissance: Identify internet-facing or internally accessible UniFi Network Application instances running versions prior to 9.0.118, 10.1.89, or 10.2.97 using network scanning tools (e.g., Shodan, Censys, or internal asset inventory).
  2. Obtain authenticated access: Acquire valid low-privilege credentials to the UniFi Network Application — this could be through phishing, credential stuffing, or use of default/weak credentials on the management interface.
  3. Identify injectable endpoints: Probe the application's API endpoints that interact with the MongoDB backend, looking for parameters that are passed directly into NoSQL queries without proper sanitization.
  4. Craft NoSQL injection payload: Inject MongoDB operator expressions (e.g., {"$gt": ""} or {"$where": "..."}) into vulnerable query parameters to manipulate query logic and bypass access controls.
  5. Escalate privileges: Leverage the injected query to retrieve or modify data associated with higher-privileged accounts, such as administrator credentials, session tokens, or role assignments.
  6. Access sensitive data: With escalated privileges, enumerate network configurations, device credentials, and other sensitive information stored within the UniFi Network Application (Ubiquiti Advisory, Bishop Fox).

Indicators of compromise

  • Network: Unusual or repeated API requests from low-privilege user accounts to administrative endpoints; anomalous query patterns in HTTP request bodies containing MongoDB operators (e.g., $gt, $where, $ne, $regex).
  • Logs: UniFi Network Application access logs showing authenticated requests with JSON payloads containing NoSQL operator syntax; unexpected privilege changes or access to admin-level resources by non-admin accounts.
  • Application Behavior: Low-privilege accounts suddenly accessing configuration data, device lists, or user management functions outside their normal scope; unexpected account role changes in the UniFi user database.
  • File System: Unusual exports or downloads of network configuration data initiated by non-administrative sessions (Ubiquiti Advisory).

Mitigation and workarounds

Ubiquiti has released patched versions of the UniFi Network Application: 9.0.118, 10.1.89, and 10.2.97. Administrators should upgrade to the appropriate patched version for their release branch immediately (Ubiquiti Advisory). As interim mitigations, restrict authenticated access to the UniFi Network Application to trusted users and networks only, implement network segmentation to limit direct access to the management interface, and monitor application logs for suspicious query patterns indicative of injection attempts (Feedly).

Community reactions

The vulnerability received broad coverage from security media outlets including CyberScoop, Cybersecurity News, Security Affairs, Heise, and BleepingComputer, often discussed alongside the critical CVE-2026-22557 path traversal flaw disclosed at the same time (CyberScoop, Security Affairs). The Belgian Centre for Cybersecurity (CCB) and Singapore's CSA both issued advisories urging immediate patching (CSA Advisory). Bishop Fox published a detailed technical blog post on detecting and weaponizing the related CVE-2026-22557, which drew significant community attention to the broader UniFi security posture (Bishop Fox). Truesec and runZero also published analyses of the vulnerabilities, and the disclosure was featured in The Hacker News weekly recap (Truesec, runZero).

Additional resources


SourceThis report was generated using AI

Related Ubiquiti UniFi vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55114HIGH8.8
  • Ubiquiti UniFi logoUbiquiti UniFi
  • cpe:2.3:a:ui:unifi_network_application
NoYesJul 02, 2026
CVE-2026-54406HIGH8.7
  • Ubiquiti UniFi logoUbiquiti UniFi
  • cpe:2.3:a:ui:unifi_network_application
NoYesJul 02, 2026
CVE-2026-55118HIGH8.3
  • Ubiquiti UniFi logoUbiquiti UniFi
  • cpe:2.3:a:ui:unifi_network_application
NoYesJul 02, 2026
CVE-2026-56842HIGH7.5
  • Ubiquiti UniFi logoUbiquiti UniFi
  • cpe:2.3:a:ui:unifi_network_application
NoYesJul 02, 2026
CVE-2026-54405HIGH7.5
  • Ubiquiti UniFi logoUbiquiti UniFi
  • cpe:2.3:a:ui:unifi_network_application
NoYesJul 02, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management