Home

Description

A series of Improper Input Validation vulnerabilities could allow a Command Injection by a malicious actor with access to the UniFi Play network. Affected Products: UniFi Play PowerAmp (Version 1.0.35 and earlier) UniFi Play Audio Port (Version 1.0.24 and earlier) Mitigation: Update UniFi Play PowerAmp to Version 1.0.38 or later Update UniFi Play Audio Port to Version 1.1.9 or later

PUBLISHED Reserved 2026-01-07 | Published 2026-04-13 | Updated 2026-04-14 | Assigner hackerone




CRITICAL: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Problem types

CWE-20 Improper Input Validation

Product status

Default status
unaffected

Any version before 1.0.38
affected

Default status
unaffected

Any version before 1.1.9
affected

References

community.ui.com/...063/e468dd4b-5090-4ef8-89d8-939903c08e83

cve.org (CVE-2026-22563)

nvd.nist.gov (CVE-2026-22563)

Download JSON