Critical UniFi Play Flaw: SSH Access Hijack Risk

Critical UniFi Play Flaw: SSH Access Hijack Risk

A critical improper access control vulnerability, identified as CVE-2026-22564, poses a significant risk to UniFi Play PowerAmp and Audio Port devices. According to the National Vulnerability Database, this flaw could allow a malicious actor with access to the UniFi Play network to enable SSH. Once SSH is enabled, an attacker could make unauthorized and potentially damaging changes to the system.

The National Vulnerability Database has assigned this vulnerability a CVSS score of 9.8, categorizing it as CRITICAL. This is a severe weakness, falling under CWE-284, which highlights the broad issue of improper access control. The affected products include UniFi Play PowerAmp, specifically versions 1.0.35 and earlier, and UniFi Play Audio Port, versions 1.0.24 and earlier. This isn’t just a theoretical threat; unauthorized SSH access is a clear path to full system compromise.

Ubiquiti, the vendor, has rolled out patches to mitigate this risk. To secure their deployments, users of UniFi Play PowerAmp should update to version 1.0.38 or later. Similarly, UniFi Play Audio Port users need to update to version 1.1.9 or later. Proactive patching is the only way to shut down this attack vector and prevent potential network breaches.

Indicators of Compromise

IDTypeIndicator
CVE-2026-22564 Auth Bypass UniFi Play PowerAmp version 1.0.35 and earlier
CVE-2026-22564 Auth Bypass UniFi Play Audio Port version 1.0.24 and earlier
CVE-2026-22564 Improper Access Control Ability to enable SSH to make unauthorized system changes on UniFi Play network devices
🔎
Turn this CVE into SIEM detection coverage Generate detection rules for Splunk, Sentinel, QRadar & Elastic — straight from this vulnerability. Use /detect in the Intel Bot.
Open Intel Bot →

Related Posts

Critical RCE Flaw Hits NuGet Gallery Backend

CVE-2026-39399 — NuGet Gallery is a package repository that powers nuget.org. A security vulnerability exists in the NuGetGallery backend job’s handling of .nuspec files within...

vulnerabilityCVEcriticalhigh-severityremote-code-executioncwe-20cwe-22
/CRITICAL /⚑ 4 IOCs

BoidCMS LFI to RCE: A Critical Template Flaw

CVE-2026-39387 — BoidCMS is an open-source, PHP-based flat-file CMS for building simple websites and blogs, using JSON as its database. Versions prior to 2.1.3 are...

vulnerabilityCVEhigh-severityremote-code-executioncwe-98
/HIGH /⚑ 4 IOCs

Nanobot AI: WebSocket Hijack Puts WhatsApp Sessions at Risk

CVE-2026-35589 — nanobot is a personal AI assistant. Versions prior to 0.1.5 contain a Cross-Site WebSocket Hijacking (CSWSH) vulnerability exists in the bridge's WebSocket server...

vulnerabilityCVEhigh-severitycwe-1385
/HIGH /⚑ 5 IOCs