CVE-2026-22558
7.7Ubiquiti Inc · UniFi Network Application
An authenticated NoSQL injection vulnerability in the UniFi Network Application allows an authenticated user to escalate privileges.
Executive summary
A critical NoSQL injection vulnerability in the Ubiquiti UniFi Network Application allows an authenticated attacker to escalate their privileges within the system.
Vulnerability
This flaw is a NoSQL injection vulnerability occurring within the UniFi Network Application. It requires the attacker to possess authenticated access to the network to successfully trigger the injection and achieve privilege escalation.
Business impact
The ability for an authenticated user to escalate privileges poses a significant risk to the integrity and confidentiality of the network management environment. With elevated privileges, an attacker could potentially gain administrative control over the network infrastructure, leading to unauthorized configuration changes, data exfiltration, or complete system compromise. Given the CVSS score of 7.7, this vulnerability represents a high-risk entry point for lateral movement within the enterprise network.
Remediation
Immediate Action: Update the UniFi Network Application to version 10.1.89, 10.2.97, 9.0.118, or newer immediately.
Proactive Monitoring: Review administrative audit logs for unusual activities and monitor database query performance for anomalous patterns that may indicate injection attempts.
Compensating Controls: Implement strict network segmentation and restrict access to the UniFi management interface to trusted administrative subnets to minimize the attack surface.
Exploitation status
Public Exploit Available: false
Analyst recommendation
The privilege escalation risk presented by this NoSQL injection vulnerability necessitates immediate attention. Administrators should prioritize upgrading the UniFi Network Application to the versions specified in the vendor security advisory. Failure to patch these instances leaves the network infrastructure susceptible to internal threats and unauthorized administrative access.