Authenticated NoSQL Injection Risk in UniFi Network Application by Ubiquiti
CVE-2026-22558
7.7HIGH
What is CVE-2026-22558?
An authenticated NoSQL injection vulnerability has been identified in Ubiquiti's UniFi Network Application, which enables malicious actors with authenticated access to exploit this flaw. By leveraging this vulnerability, attackers can potentially escalate their privileges within the network, compromising sensitive data and overall security integrity. It is crucial for network administrators to review their systems and implement necessary security measures to mitigate this risk.
Affected Version(s)
UniFi Network Application 10.1.89
UniFi Network Application 10.2.97
UniFi Network Application 9.0.118
