Critical Ubiquiti UniFi UniFi security flaw allows potential account hijacking
好的,我现在需要帮用户总结一篇文章的内容,控制在100个字以内。用户的要求很明确,不需要用“文章内容总结”或“这篇文章”这样的开头,直接写描述即可。 首先,我仔细阅读了用户提供的文章内容。文章主要讲的是Ubiquiti公司修复了其UniFi Network应用中的两个漏洞,其中一个漏洞的严重程度是最高级别的,可能导致账户接管。另一个漏洞则涉及权限提升。 接下来,我需要提取关键信息:修复了两个漏洞,一个是最高严重性的账户接管风险,另一个是权限提升漏洞。然后,我需要将这些信息浓缩到100字以内。 考虑到用户可能的需求,他们可能需要一个简洁明了的总结,用于快速了解文章内容。因此,我应该避免使用复杂的术语,并确保信息准确无误。 最后,我会组织语言,确保句子流畅且信息完整。例如:“Ubiquiti修复了UniFi Network应用中的两个漏洞:一个是最高严重性的账户接管风险(CVE-2026-22557),另一个是权限提升漏洞(CVE-2026-22558)。” 这样既满足了字数限制,又涵盖了所有关键点。 </think> Ubiquiti修复了UniFi Network应用中的两个漏洞:一个是最高严重性的账户接管风险(CVE-2026-22557),另一个是权限提升漏洞(CVE-2026-22558)。 2026-3-19 21:21:24 Author: securityaffairs.com(查看原文) 阅读量:4 收藏

Critical Ubiquiti UniFi UniFi security flaw allows potential account hijacking

Ubiquiti fixed two UniFi vulnerabilities, including a critical flaw that could let attackers take over user accounts.

Ubiquiti patched two vulnerabilities in its UniFi Network app, including a maximum-severity flaw that could enable account takeover. The software is widely used to manage UniFi networking devices like access points, switches, and gateways.

The Ubiquiti UniFi Network app is management software developed by Ubiquiti to control and monitor its UniFi networking devices.

It lets users configure, manage, and optimize hardware like Wi-Fi access points, switches, and gateways from a single dashboard. IT admins use it to set up networks, track performance, manage users, apply security settings, and troubleshoot issues, either locally or via the cloud.

The vendor addressed a maximum severity issue tracked as CVE-2026-22557 (CVSS score of 10.0), which affects UniFi Network application version 10.1.85 and earlier.

An attacker on the network could exploit a path traversal flaw in UniFi to access system files and potentially take over user accounts.

“A malicious actor with access to the network could exploit a Path Traversal vulnerability found in the UniFi Network Application to access files on the underlying system that could be manipulated to access an underlying account.” reads the advisory.

Versions 10.1.89 or later addressed the vulnerability.

The second issue addressed by Ubiquiti, tracked as CVE-2026-22558 (CVSS score of 7.7), resides in the UniFi Network app, attackers with low privileges can exploit it for privilege escalation.

“An Authenticated NoSQL Injection vulnerability found in UniFi Network Application could allow a malicious actor with authenticated access to the network to escalate privileges,” states the company.

Pierluigi Paganini

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

(SecurityAffairs – hacking, UniFi Network Application)




文章来源: https://securityaffairs.com/189689/security/critical-ubiquiti-unifi-unifi-security-flaw-allows-potential-account-hijacking.html
如有侵权请联系:admin#unsafe.sh