Affected Products:
UniFi Play PowerAmp (Version 1.0.35 and earlier)
UniFi Play Audio Port (Version 1.0.24 and earlier)
Mitigation:
Update UniFi Play PowerAmp to Version 1.0.38 or later
Update UniFi Play Audio Port to Version 1.1.9 or later
Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 14 Apr 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Improper Access Control in Ubiquiti UniFi Play Devices Enables Unauthorized Retrieval of WiFi Credentials |
Tue, 14 Apr 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ubiquiti
Ubiquiti unifi Play Audio Port Ubiquiti unifi Play Poweramp |
|
| Vendors & Products |
Ubiquiti
Ubiquiti unifi Play Audio Port Ubiquiti unifi Play Poweramp |
Tue, 14 Apr 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 13 Apr 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An Improper Access Control vulnerability could allow a malicious actor with access to the UniFi Play network to obtain UniFi Play WiFi credentials. Affected Products: UniFi Play PowerAmp (Version 1.0.35 and earlier) UniFi Play Audio Port (Version 1.0.24 and earlier) Mitigation: Update UniFi Play PowerAmp to Version 1.0.38 or later Update UniFi Play Audio Port to Version 1.1.9 or later | |
| Weaknesses | CWE-284 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2026-04-14T13:14:19.836Z
Reserved: 2026-01-07T15:39:03.441Z
Link: CVE-2026-22566
Updated: 2026-04-14T13:09:35.166Z
Status : Received
Published: 2026-04-13T22:16:28.437
Modified: 2026-04-13T22:16:28.437
Link: CVE-2026-22566
No data.
OpenCVE Enrichment
Updated: 2026-04-14T16:33:03Z