Skip to main content

Description

A malicious actor with access to the network could exploit a Path Traversal vulnerability found in the UniFi Network Application to access files on the underlying system that could be manipulated to access an underlying account.

Severity

CVSS 3.1 · CNA10 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
SSVC · CISA-ADP
Exploitationnone
Automatableyes
Technical impacttotal

Affected Products

VendorProductAffected versions
Ubiquiti IncUniFi Network Application
10.1.89 to <10.1.89
10.2.97 to <10.2.97
9.0.118 to <9.0.118

References

1 Links

Record Details

Published
2026-03-19
Last updated
2026-03-19
Assigner (CNA)
hackerone
Credited to
-

CVE record data © The MITRE Corporation, used under the CVE Terms of Use. Exploited-in-the-wild data from the CISA Known Exploited Vulnerabilities catalog (CC0). Exploit prediction scores by FIRST EPSS (first.org/epss). This site is not endorsed or certified by MITRE, NVD, CISA, or FIRST.