Description
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect Application to bypass authentication in certain UniFi Protect Application API endpoints.
Published: 2026-07-02
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A malicious actor with network access can exploit an Improper Access Control flaw in the UniFi Protect Application to bypass authentication on specific API endpoints, allowing unauthorized use of protected resources.

Affected Systems

The issue affects Ubiquiti Inc.'s UniFi Protect Application. No vendor‑provided version numbers are listed, and the specific versions affected are not disclosed.

Risk and Exploitability

The CVSS score of 8.6 indicates high severity, while the EPSS score of <1% reflects a very low likelihood of exploitation and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves a malicious actor with local or network access to the UniFi Protect API, exploiting the access‑control flaw to reach unauthorized endpoints.

Generated by OpenCVE AI on July 21, 2026 at 11:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check the vendor’s latest advisories or support portal for a fix or update addressing this access-control flaw.
  • Regenerate all existing API keys and enforce strong authentication controls to prevent misuse of compromised credentials.
  • Apply network segmentation or firewall rules to restrict access to the UniFi Protect API endpoints so that only trusted management devices can reach them.

Generated by OpenCVE AI on July 21, 2026 at 11:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 21 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title Improper Access Control in UniFi Protect API Enables Authentication Bypass

Wed, 15 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
Title Authentication Bypass in UniFi Protect API

Mon, 13 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Authentication Bypass in UniFi Protect API

Mon, 13 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Unauthorized API Access via Authentication Bypass in Ubiquiti UniFi Protect

Sat, 11 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Unauthorized API Access via Authentication Bypass in Ubiquiti UniFi Protect

Fri, 10 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Title Improper Access Control in UniFi Protect Allowing Authentication Bypass

Thu, 09 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Improper Access Control in UniFi Protect Allowing Authentication Bypass

Thu, 09 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Title Authentication Bypass in UniFi Protect API Endpoints

Wed, 08 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Authentication Bypass in UniFi Protect API Endpoints

Tue, 07 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title Improper Access Control in UniFi Protect API Enables Authentication Bypass

Tue, 07 Jul 2026 00:00:00 +0000

Type Values Removed Values Added
Title Improper Access Control in UniFi Protect API Enables Authentication Bypass

Mon, 06 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
Title API Authentication Bypass via Improper Access Control in Ubiquiti UniFi Protect

Sun, 05 Jul 2026 18:00:00 +0000

Type Values Removed Values Added
Title API Authentication Bypass via Improper Access Control in Ubiquiti UniFi Protect

Sun, 05 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Ubiquiti UniFi Protect API Enables Authentication Bypass

Sun, 05 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Ubiquiti UniFi Protect API Enables Authentication Bypass

Sat, 04 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Improper Access Control in UniFi Protect API Allows Authentication Bypass

Sat, 04 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
Title Improper Access Control in UniFi Protect API Allows Authentication Bypass

Fri, 03 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Authentication Bypass in UniFi Protect Application API Endpoints

Fri, 03 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
Title Authentication Bypass in UniFi Protect Application API Endpoints

Thu, 02 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Description A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect Application to bypass authentication in certain UniFi Protect Application API endpoints.
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2026-07-02T16:08:49.302Z

Reserved: 2026-06-13T15:00:00.605Z

Link: CVE-2026-54407

cve-icon Vulnrichment

Updated: 2026-07-02T16:08:46.492Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T11:30:06Z

Weaknesses