Date: Thu, 19 Mar 2026 19:03:36 +0000
From: Fernando Apeste=?utf-8?Q?gu=C3=ADa?= <fernape@FreeBSD.org>
To: ports-committers@FreeBSD.org, dev-commits-ports-all@FreeBSD.org, dev-commits-ports-main@FreeBSD.org
Subject: git: 70d765816c1d - main - security/vuxml: Add unifi{9,10} vulnerabilities
Message-ID: <69bc4888.3ff5e.1630dbb9@gitrepo.freebsd.org>
index | next in thread | raw e-mail
The branch main has been updated by fernape: URL: https://cgit.FreeBSD.org/ports/commit/?id=70d765816c1d187ee464646d9d8958f48261b28d commit 70d765816c1d187ee464646d9d8958f48261b28d Author: Fernando ApesteguĂa <fernape@FreeBSD.org> AuthorDate: 2026-03-19 19:00:45 +0000 Commit: Fernando ApesteguĂa <fernape@FreeBSD.org> CommitDate: 2026-03-19 19:00:45 +0000 security/vuxml: Add unifi{9,10} vulnerabilities CVE: CVE-2026-22557 Base Score: 10.0 (Critical) CVSS: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H CVE: CVE-2026-22558 Base Score: 7.7 (High) CVSS: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N Reported by: Jana Steuernagel --- security/vuxml/vuln/2026.xml | 40 ++++++++++++++++++++++++++++++++++++++++ 1 file changed, 40 insertions(+) diff --git a/security/vuxml/vuln/2026.xml b/security/vuxml/vuln/2026.xml index b0e3e1dfda71..b7a57e768eba 100644 --- a/security/vuxml/vuln/2026.xml +++ b/security/vuxml/vuln/2026.xml @@ -1,3 +1,43 @@ + <vuln vid="71b4ce56-23c5-11f1-b865-b42e991fc52e"> + <topic>UniFi Network Application - Multiple vulnerabilities</topic> + <affects> + <package> + <name>unifi10</name> + <range><lt>10.1.89</lt></range> + </package> + <package> + <name>unifi9</name> + <range><lt>9.0.114</lt></range> + </package> + </affects> + <description> + <body xmlns="http://www.w3.org/1999/xhtml"> + <p>https://community.ui.com/releases/Security-Advisory-Bulletin-062-062/c29719c0-405e-4d4a-8f26-e343e99f931b reports:</p> + <blockquote cite="https://community.ui.com/releases/Security-Advisory-Bulletin-062-062/c29719c0-405e-4d4a-8f26-e343e99f931b"> + <p>An Authenticated NoSQL Injection vulnerability found in + UniFi Network Application could allow a malicious actor with + authenticated access to the network to escalate + privileges.</p> + <p>A malicious actor with access to the network could + exploit a Path Traversal vulnerability found in the UniFi + Network Application to access files on the underlying system + that could be manipulated to access an underlying + account.</p> + </blockquote> + </body> + </description> + <references> + <cvename>CVE-2026-22558</cvename> + <url>https://cveawg.mitre.org/api/cve/CVE-2026-22558</url> + <cvename>CVE-2026-22557</cvename> + <url>https://cveawg.mitre.org/api/cve/CVE-2026-22557</url> + </references> + <dates> + <discovery>2026-03-19</discovery> + <entry>2026-03-19</entry> + </dates> + </vuln> + <vuln vid="c5b93cb5-2363-11f1-81da-8447094a420f"> <topic>Roundcube -- Multiple vulnerabilities</topic> <affects>home | help
Want to link to this message? Use this
URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?69bc4888.3ff5e.1630dbb9>
