[Bug 293922] net-mgmt/unify9,10 security vulnerabilities
Date: Thu, 19 Mar 2026 19:05:29 UTC
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=293922
Bug ID: 293922
Summary: net-mgmt/unify9,10 security vulnerabilities
Product: Ports & Packages
Version: Latest
Hardware: Any
OS: Any
Status: New
Severity: Affects Only Me
Priority: ---
Component: Individual Port(s)
Assignee: ports-bugs@FreeBSD.org
Reporter: fernape@FreeBSD.org
From Jana Steuernagel
Unifi has published a security advisory for the Unifi Controller version
10.1.85 and below, which is the current version on Ports.
It includes 2 CVEs, one with a score of 10.0, allowing path traversal to access
files on the underlying system, and a 7.7 NoSQL injection, allowing privilege
escalation for authenticated users.
https://community.ui.com/releases/Security-Advisory-Bulletin-062-062/c29719c0-405e-4d4a-8f26-e343e99f931b
A patched version 10.1.89 is available and it would be great if that could be
updated in Ports soon:
https://community.ui.com/releases/UniFi-Network-Application-10-1-89/625f366f-7ea5-4266-bd9f-500180494035
--
You are receiving this mail because:
You are the assignee for the bug.