A malicious actor with access to the network could exploit a Path Traversal vulnerability found in the UniFi Network Application to access files on the underlying system that could be manipulated to access an underlying account.
[POC] GHSA-2j8v-hwgc-x698 — CVE-2026-22557-Path-Traversal-Ubiquti-UniFi
CVE-2026-22557 Path Traversal Ubiquti UniFi Network Application
PoC: CVE-2026-22557-check
Safely detect whether a UniFi Network Application controller is vulnerable to CVE-2026-22557
PoC: CVE-2026-22557-PoC
PoC for UniFi Network Application Pre-Auth Path Traversal (CVE-2026-22557)
PoC: CVE-2026-22557
CVE-2026-22557
PoC: cve-2026-22557-unifi-detection
Detection content for CVE-2026-22557 — UniFi Network Application unauthenticated path traversal (CVSS 10.0). Includes YARA, Sigma, KQL, Splunk SPL, Sysmon config, and a bash detection script.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free