FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

UniFi Network Application - Multiple vulnerabilities

Affected packages
unifi10 < 10.1.89
unifi9 < 9.0.114

Details

VuXML ID 71b4ce56-23c5-11f1-b865-b42e991fc52e
Discovery 2026-03-19
Entry 2026-03-19

https://community.ui.com/releases/Security-Advisory-Bulletin-062-062/c29719c0-405e-4d4a-8f26-e343e99f931b reports:

An Authenticated NoSQL Injection vulnerability found in UniFi Network Application could allow a malicious actor with authenticated access to the network to escalate privileges.

A malicious actor with access to the network could exploit a Path Traversal vulnerability found in the UniFi Network Application to access files on the underlying system that could be manipulated to access an underlying account.

References

CVE Name CVE-2026-22557
CVE Name CVE-2026-22558
URL https://cveawg.mitre.org/api/cve/CVE-2026-22557
URL https://cveawg.mitre.org/api/cve/CVE-2026-22558