
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-22558 is an authenticated NoSQL injection vulnerability in Ubiquiti's UniFi Network Application that allows a malicious actor with authenticated network access to escalate privileges and access sensitive data. It was published on March 19, 2026, and assigned by HackerOne. Affected versions are UniFi Network Application prior to 9.0.118, 10.1.89, and 10.2.97 (Ubiquiti Advisory, ENISA EUVD). The vulnerability carries a CVSS v3.1 base score of 7.7 (High) with a changed scope, reflecting its potential to impact resources beyond the vulnerable component (Feedly).
The vulnerability is classified as CWE-943 (Improper Neutralization of Special Elements in Data Query Logic), specifically a NoSQL injection flaw (CAPEC-676) in the UniFi Network Application's backend query handling (Feedly). An authenticated attacker can craft malicious query inputs that bypass intended data access controls in the MongoDB-backed application, enabling privilege escalation. The attack requires only low privileges, no user interaction, and is exploitable remotely over the network (ENISA EUVD). A technical write-up and weaponization analysis has been published by Bishop Fox covering this and the related CVE-2026-22557 (Bishop Fox).
Successful exploitation allows an authenticated attacker to escalate privileges within the UniFi Network Application, gaining unauthorized access to sensitive network configuration data and potentially other users' account information. The CVSS scoring reflects a high confidentiality impact with a changed scope, meaning the attacker can access data beyond their authorized boundary — including network topology, device credentials, and administrative settings. Integrity and availability are not directly impacted by this vulnerability, but privilege escalation could serve as a stepping stone for further compromise of managed network infrastructure (Feedly, ENISA EUVD).
As of the time of reporting, there is no public proof-of-concept exploit specifically for CVE-2026-22558, and no confirmed in-the-wild exploitation has been observed (Feedly). The EPSS score is approximately 0.026%, indicating a low current probability of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Bishop Fox has published a blog post analyzing and weaponizing the related CVE-2026-22557 (a critical path traversal flaw disclosed simultaneously), which may lower the barrier for chained exploitation (Bishop Fox).
{"$gt": ""} or {"$where": "..."}) into vulnerable query parameters to manipulate query logic and bypass access controls.$gt, $where, $ne, $regex).Ubiquiti has released patched versions of the UniFi Network Application: 9.0.118, 10.1.89, and 10.2.97. Administrators should upgrade to the appropriate patched version for their release branch immediately (Ubiquiti Advisory). As interim mitigations, restrict authenticated access to the UniFi Network Application to trusted users and networks only, implement network segmentation to limit direct access to the management interface, and monitor application logs for suspicious query patterns indicative of injection attempts (Feedly).
The vulnerability received broad coverage from security media outlets including CyberScoop, Cybersecurity News, Security Affairs, Heise, and BleepingComputer, often discussed alongside the critical CVE-2026-22557 path traversal flaw disclosed at the same time (CyberScoop, Security Affairs). The Belgian Centre for Cybersecurity (CCB) and Singapore's CSA both issued advisories urging immediate patching (CSA Advisory). Bishop Fox published a detailed technical blog post on detecting and weaponizing the related CVE-2026-22557, which drew significant community attention to the broader UniFi security posture (Bishop Fox). Truesec and runZero also published analyses of the vulnerabilities, and the disclosure was featured in The Hacker News weekly recap (Truesec, runZero).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."