LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-22564

CVE-2026-22564 - Vulnerability Analysis

CriticalCVSS: 9.8

Last Updated: April 13, 2026

UniFi Play - Broken Access Control

Published: April 13, 2026Updated: April 13, 2026Remote Exploitable

Overview

UniFi Play PowerAmp <= 1.0.35 and UniFi Play Audio Port <= 1.0.24 contain an improper access control vulnerability allowing malicious actors with network access to enable SSH and make unauthorized system changes, exploit requires network access.

Severity & Score

Severity: Critical
CVSS Score: 9.8
EPSS Score: 0.0%(Probability of exploitation in next 30 days)

Impact

Malicious actors can enable SSH and make unauthorized changes to the system, potentially compromising device integrity.

Mitigation

Update UniFi Play PowerAmp to version 1.0.38 or later and UniFi Play Audio Port to version 1.1.9 or later.

Social Media Activity(2 posts)

TheHackerWire
TheHackerWire
@thehackerwire
Apr 13, 2026

šŸ”“ CVE-2026-22564 - Critical (9.8) An Improper Access Control vulnerability could allow a malicious actor with access to the UniFi Play network to enable SSH to make unauthorized changes to the system.
 Affected Products: UniFi Play PowerAmp (Version 1.0.35 and earlier)
 UniF... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-22564/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post
TheHackerWire
TheHackerWire
@thehackerwire
Apr 13, 2026

šŸ”“ CVE-2026-22564 - Critical (9.8) An Improper Access Control vulnerability could allow a malicious actor with access to the UniFi Play network to enable SSH to make unauthorized changes to the system.
 Affected Products: UniFi Play PowerAmp (Version 1.0.35 and earlier)
 UniF... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-22564/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post

Details

CVE ID
CVE-2026-22564
Severity
Critical
CVSS Score
9.8
Type
broken_access_control
Status
new
EPSS
0.0%
Social Posts
2

CWE

  • CWE-284

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Score

0.0%Probability of exploitation in the next 30 days