Security Digest: June 12, 2026 - 11 Critical Vulnerabilities
Today’s disclosures include seven critical vulnerabilities that can lead to privilege escalation, command injection, or account takeover, plus several high-severity issues that can crash services or widen access in admin tools. The most urgent fixes are for UniFi OS devices, WordPress Toolkit in cPanel & WHM, IEI iRM-IEI Remote Management, and OAuth implementations with flawed authentication checks.
· 9 min read
Urgent Security Alert: Multiple Critical Flaws in UniFi OS, WordPress Toolkit, OAuth, and More
Executive Summary
Today’s disclosures include seven critical vulnerabilities that can lead to privilege escalation, command injection, or account takeover, plus several high-severity issues that can crash services or widen access in admin tools. The most urgent fixes are for UniFi OS devices, WordPress Toolkit in cPanel & WHM, IEI iRM-IEI Remote Management, and OAuth implementations with flawed authentication checks.
Teams should patch exposed systems immediately, restrict network access to management interfaces, and review admin accounts and OAuth configurations for signs of abuse. If you operate any affected platform, treat this as a same-day remediation event.
Critical Vulnerabilities
CVE-2026-47369: UniFi OS privilege escalation via input validation flaw
- Impact: A network-accessible attacker with low privileges could escalate privileges inside affected UniFi OS devices or instances.
- Affected Systems: Certain devices running UniFi OS.
- Immediate Action: Apply the vendor fix as soon as it is available; limit management access to trusted networks only.
- Mitigation: Restrict exposure of UniFi management services, enforce MFA for admins, and monitor for unexpected privilege changes.
CVE-2026-47365: WordPress Toolkit argument injection in cPanel & WHM
- Impact: Remote authenticated users may bypass cross-tenant controls and run wp-toolkit CLI commands as another account.
- Affected Systems: WordPress Toolkit before
6.11.0as used in cPanel & WHM. - Immediate Action: Upgrade WordPress Toolkit to
6.11.0or later immediately. - Mitigation: Review tenant isolation, rotate privileged credentials, and audit recent wp-toolkit activity for abuse.
CVE-2026-47370: UniFi OS command injection
- Impact: A low-privilege network attacker could execute commands on affected UniFi OS devices or instances.
- Affected Systems: Certain devices running UniFi OS.
- Immediate Action: Patch immediately and isolate any internet-facing management endpoints.
- Mitigation: Block unnecessary inbound access, place admin interfaces behind VPN or allowlists, and review logs for suspicious command execution.
CVE-2026-47367: UID Enterprise Agent command injection
- Impact: Attackers with network access and low privileges could run commands on the host device.
- Affected Systems: UID Enterprise Agent.
- Immediate Action: Update the agent on all hosts and remove unnecessary network exposure.
- Mitigation: Segment management traffic, verify host integrity, and look for unexpected child processes or shell activity.
CVE-2026-11849: IEI iRM-IEI Remote Management hardcoded credentials
- Impact: Unauthenticated attackers can use hardcoded credentials to gain administrative database access.
- Affected Systems: iRM-IEI Remote Management by IEI Integration Corp.
- Immediate Action: Disconnect exposed instances from the internet and apply vendor remediation immediately.
- Mitigation: Replace any embedded credentials, rotate database and admin passwords, and verify whether any unauthorized logins occurred.
CVE-2026-48611: OAuth account hijacking in default installations
- Impact: Improper authentication checks can allow account hijacking even when OAuth is not configured or enabled.
- Affected Systems: Products using the affected OAuth implementation in default installations.
- Immediate Action: Identify all deployments using the vulnerable OAuth component and patch immediately.
- Mitigation: Disable or isolate unused auth paths, force reauthentication for users, and review account link activity for anomalies.
CVE-2026-12059: CelloOS SSH command restriction bypass
- Impact: Authenticated remote attackers can bypass command restrictions and execute OS commands outside the intended scope.
- Affected Systems: SSH service in CelloOS by Cellopoint.
- Immediate Action: Restrict SSH access to trusted admins only and apply vendor updates immediately.
- Mitigation: Enforce key-based authentication, review command logs, and remove broad SSH access from non-admin accounts.
CVE-2026-48612: OAuth state verification flaw leading to account linking abuse
- Impact: Attackers may manipulate the auth flow to link a victim account to an attacker-controlled account, enabling takeover.
- Affected Systems: Products using the affected OAuth implementation.
- Immediate Action: Patch the OAuth implementation and force re-linking of external identity providers where needed.
- Mitigation: Require step-up authentication for account linking and review recent linking events and login anomalies.
CVE-2026-44892: Netty HTTP/3 header exhaustion denial of service
- Impact: A malicious peer can send excessive headers and exhaust memory, causing service crashes or outages.
- Affected Systems: Netty HTTP/3 codec prior to
4.2.15.Final. - Immediate Action: Upgrade to
4.2.15.Finalor later now. - Mitigation: Enforce header limits at the edge, rate-limit HTTP/3 traffic, and monitor for memory spikes or
OutOfMemoryErrorevents.
CVE-2026-47366: Administration Control Panel privilege escalation
- Impact: An authenticated administrator can grant permissions beyond their authorized level.
- Affected Systems: Systems using the affected Administration Control Panel.
- Immediate Action: Patch immediately and review all recent permission changes made through the ACP.
- Mitigation: Enforce least privilege, require approval for elevated access, and audit admin-role changes for misuse.
What to Do Now
- Patch exposed systems first: UniFi OS, WordPress Toolkit
6.11.0+, UID Enterprise Agent, IEI iRM-IEI Remote Management, CelloOS SSH, OAuth components, Netty4.2.15.Final+, and ACP-managed platforms. - Reduce attack surface: Remove internet exposure from admin panels and SSH, use VPN or IP allowlists, and disable unused services.
- Check for abuse: Review logs for privilege changes, unusual account linking, unexpected CLI execution, and suspicious SSH or command activity.
- Reset and revalidate access: Rotate admin credentials, API keys, and database passwords where hardcoded or elevated access may have been exposed.
- Verify versions: Confirm vulnerable components are no longer present and document remediation for each affected host.
Verification steps: inventory all internet-facing management tools, confirm package and firmware versions, validate OAuth and SSO settings, and test that patched systems reject unauthorized access.
Monitoring recommendations: alert on new admin creation, permission changes, OAuth account-link events, shell spawning from management services, database logins with shared credentials, and memory exhaustion or crash loops in HTTP/3 services.
Related Resources
- Internal blog posts: Reference our upcoming remediation guide for UniFi OS, cPanel & WHM, and OAuth account-takeover defenses.
- Official vendor advisories: Monitor advisories from Ubiquiti, cPanel/WordPress Toolkit, IEI Integration Corp., Cellopoint, MongoDB, Netty, and the OAuth component vendor for patch details and timelines.