S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jun 22, 2026

CVE-2026-22557 Scanner

CVE-2026-22557 Scanner - Path Traversal vulnerability in UniFi Network Application

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.7k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2026-22557
10.0
CVSScritical
Exploitable remotely over the internet · no authentication required.

A malicious actor with access to the network could exploit a Path Traversal vulnerability found in the UniFi Network Application to access files on the underlying system that could be manipulated to access an underlying account.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
UniFi Network Applicationby Ubiquiti Inc
AFFECTED< 10.1.89SAFE ✓≥ 10.1.89
Updated Aug 22, 2026View on NVD →
Detail

The UniFi Network Application is widely used by network administrators and IT professionals to manage networking devices from Ubiquiti Networks. It provides a comprehensive platform for setting up, managing, and monitoring networks, supporting devices such as routers, switches, and access points. This software is utilized in diverse environments, including enterprise offices, educational institutions, and large-scale networks, thanks to its robust scalability and management capabilities. The intuitive interface and versatility make UniFi a preferred choice for centralized network administration. The software also facilitates seamless network security and configuration, essential for maintaining network integrity and performance.

The path traversal vulnerability in the UniFi Network Application is critical as it potentially allows unauthorized users to access restricted directories and manipulate files. This flaw can have significant security implications, including unauthorized access to sensitive user data and system files. Attackers exploiting this vulnerability can bypass security controls and gain higher access privileges, posing a severe threat to network security. Given the critical nature of this vulnerability, it is of utmost importance for users of the UniFi Network Application to address this issue promptly.

In this particular path traversal vulnerability, the vulnerable endpoint is the "/guest/s/default/login" page. The vulnerability is triggered through improper handling of input within the "page_error" parameter, allowing directory traversal using the "..%2F..%2F" sequence. When combined with specific requests, this allows an attacker to access sensitive files like "web.xml", which can contain configurations and credentials. The affected parameter is exploited by sending an HTTP request specially crafted to retrieve files outside the intended directory. Ensuring proper input validation and sanitization can mitigate such vulnerabilities effectively.

If exploited, the vulnerability can lead to widespread consequences, including unauthorized access to sensitive files, account compromise, and potentially full system control. Network integrity could be severely compromised, leading to data breaches, service disruption, and reputational damage to the organization running the network. With sensitive information exposed, attackers can conduct further attacks, such as privilege escalation or injecting malicious scripts. Thus, addressing the vulnerability is crucial to protect against potential exploitation and maintaining the security posture of the network.

REFERENCES

Solution Advice
  • Ensure to update to the latest version of the UniFi Network Application to incorporate patches addressing the vulnerability.
  • Implement strong input validation and sanitization practices to prevent directory traversal attacks.
  • Regularly audit and monitor logs for suspicious activities that may indicate exploitation attempts.
  • Segregate sensitive files and directories using strict access controls to minimize unauthorized access.
  • Consider implementing runtime application self-protection (RASP) solutions to detect and block attack attempts in real-time.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.