CVE-2026-22559

8.8

Ubiquiti Inc · UniFi Network Server

An improper input validation flaw in UniFi Network Server allows unauthorized account access if a user is socially engineered into clicking a malicious link.

Executive summary

An improper input validation vulnerability in Ubiquiti UniFi Network Server poses a high risk of unauthorized account access through social engineering, necessitating an immediate software update.

Vulnerability

This vulnerability involves improper input validation in the UniFi Network Server application, which can be exploited by an unauthenticated attacker to gain unauthorized access to a victim account after the victim clicks a malicious link.

Business impact

Successful exploitation of this vulnerability could lead to a complete compromise of administrative or user accounts, resulting in unauthorized access to sensitive network configuration data and potential control over managed network infrastructure. With a CVSS score of 8.8, the vulnerability is classified as High severity because it allows for full confidentiality, integrity, and availability impact, despite the requirement for user interaction.

Remediation

Immediate Action: Update all instances of the UniFi Network Server to version 10.1.89 or later to remediate the underlying input validation flaw.

Proactive Monitoring: Review web server and application access logs for suspicious referral headers or unusual URL parameters associated with user sessions.

Compensating Controls: Deploy a Web Application Firewall (WAF) to filter malicious input and implement user awareness training to mitigate the risk of successful social engineering attacks.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the High severity rating and the potential for total account compromise, organizations should prioritize patching their UniFi Network Server instances to version 10.1.89 or later. Administrators must treat this update as a critical security requirement to prevent unauthorized access and potential lateral movement within the network infrastructure.

More Ubiquiti Inc CVEs

Sources