CVE-2026-22558 | Ubiquiti UniFi Network Application up to 9.0.117/10.1.88/10.2.96 NoSQL data query logic injection (WID-SEC-2026-0784)
A vulnerability marked as critical has been reported in Ubiquiti UniFi Network Application up to 9.0.117/10.1.88/10.2.96. Impacted is an unknown function of the component NoSQL. The manipulation leads to improper neutralization of special elements in data query logic.
This vulnerability is traded as CVE-2026-22558. It is possible to initiate the attack remotely. There is no exploit available.
It is suggested to upgrade the affected component.