
CVE-2026-22557
A critical unauthenticated path traversal vulnerability (CWE-22) exists in the Ubiquiti UniFi Network Application (UniFi Controller).
An attacker with network access can exploit this flaw to:
../)No authentication or user interaction is required.
CVSS v3.1 Base Score: 10.0 (Critical)
Vector: AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
⚠️ This is considered an emergency-level vulnerability — treat it with the highest priority.
| Product | Affected Versions | Fixed In |
|---|---|---|
| UniFi Network Application (Stable) | ≤ 10.1.85 | 10.1.89 |
| UniFi Network Application (Release Candidate) | ≤ 10.2.93 | 10.2.97 |
| UniFi Express (Firmware) | ≤ 4.0.12 (or 9.0.114 in some builds) | 4.0.13 |
Confirmed vulnerable examples:
Official Advisory: Security Advisory Bulletin 062
This vulnerability earned the maximum CVSS score of 10.0 due to its ease of exploitation and severe consequences.
1. Update Immediately
2. Temporary Workarounds (if patching is delayed)
3. Best Practice
Related Vulnerability:
Last Updated: April 2026
Disclaimer: This repository is maintained for defensive, educational, and informational purposes only. No exploit code is hosted here.
Made with ❤️ for the security community