Impact
A malicious actor with network access can exploit an Improper Access Control flaw in the UniFi Protect Application to bypass authentication on specific API endpoints, allowing unauthorized use of protected resources.
Affected Systems
The issue affects Ubiquiti Inc.'s UniFi Protect Application. No vendor‑provided version numbers are listed, and the specific versions affected are not disclosed.
Risk and Exploitability
The CVSS score of 8.6 indicates high severity, while the EPSS score of <1% reflects a very low likelihood of exploitation and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves a malicious actor with local or network access to the UniFi Protect API, exploiting the access‑control flaw to reach unauthorized endpoints.
OpenCVE Enrichment