CVE-2026-22564
Improper Access Control in UniFi Play Enables Unauthorized SSH
Publication date: 2026-04-13
Last updated on: 2026-04-13
Assigner: HackerOne
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| ubiquiti | unifi_play_poweramp | to 1.0.36 (exc) |
| ubiquiti | unifi_play_audio_port | to 1.0.25 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-284 | The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is an Improper Access Control issue in certain UniFi Play devices. It allows a malicious actor who already has access to the UniFi Play network to enable SSH access on the device. By enabling SSH, the attacker can make unauthorized changes to the system.
How can this vulnerability impact me? :
The impact of this vulnerability is severe because it allows an attacker to gain unauthorized control over affected devices. With SSH enabled, the attacker can make unauthorized system changes, potentially compromising the confidentiality, integrity, and availability of the device and any data it handles.
What immediate steps should I take to mitigate this vulnerability?
To mitigate this vulnerability, update your affected UniFi devices to the fixed versions.
- Update UniFi Play PowerAmp to Version 1.0.38 or later.
- Update UniFi Play Audio Port to Version 1.1.9 or later.
How does this vulnerability affect compliance with common standards and regulations (like GDPR, HIPAA)?:
The vulnerability allows unauthorized access via SSH to make changes to the system, which could lead to unauthorized data access or modification.
Such unauthorized access and potential data compromise could negatively impact compliance with standards and regulations like GDPR and HIPAA, which require strict access controls and protection of sensitive data.
However, specific impacts on compliance are not detailed in the provided information.