CVE-2026-22557 is a critical unauthenticated path traversal vulnerability in the Ubiquiti UniFi Network Application. The flaw affects the guest captive portal handling in the application and allows a remote attacker with network access to traverse outside the intended portal resource directory and read files from the underlying system. Public technical analysis indicates the vulnerable code path uses attacker-controlled input from a guest portal error-page parameter as a relative filesystem path without adequate validation or canonicalization before opening and streaming the referenced file. The issue has been described in the guest portal servlet and associated failure-page rendering logic, where a crafted request can trigger arbitrary file disclosure from the controller host. The vulnerability is especially dangerous because exposed files may include application configuration, backups, database content, and credential material that can then be used to compromise accounts managed by or underlying the controller. The vulnerability has been assigned a CVSS v3.1 score of 10.0.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (4 hidden).
This repository is a small standalone proof-of-concept exploit for CVE-2026-22557 affecting the Ubiquiti UniFi Network Application guest portal. The repo contains two files: a single Python exploit script (CVE-2026-22557.py) and a README with usage examples. The Python script is the clear entry point and uses requests/urllib3 to send an unauthenticated HTTP GET request to the guest portal login endpoint, defaulting to /guest/s/default/login. It appends the page_error parameter with a relative traversal path, default ../../web.xml, and sets a crafted Referer header that imitates expected guest portal traffic. The exploit supports custom target URLs, custom guest portal paths, arbitrary file/resource paths, optional output-to-file, and optional HTTP proxying. It handles redirects and basic failure cases, and prints or saves the retrieved content when successful. The exploit’s main capability is pre-auth arbitrary file read/path traversal; it does not provide code execution, persistence, or post-exploitation features. The README states that customized guest portals may potentially allow access beyond the webapp context via a FileInputStream fallback, but this is presented as unconfirmed. Overall, this is a focused, functional PoC for unauthenticated file disclosure over the web/network attack surface.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
57 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical arbitrary file read / path traversal vulnerability in UniFi Network's guest portal login endpoint, where the page_error parameter can be manipulated to retrieve internal files such as WEB-INF/web.xml.
A prior Ubiquiti vulnerability mentioned only in vendor security history context.
A previously disclosed Ubiquiti UniFi Network Application vulnerability mentioned only as part of the vendor's broader 2026 security history.
A previously disclosed critical path traversal vulnerability in the UniFi Network Application, mentioned as background on Ubiquiti's 2026 security history.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.