Description
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect Application to bypass authentication for data streaming.
Published: 2026-07-02
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an Improper Access Control flaw (CWE‑284) in the UniFi Protect Application that allows an attacker with network access to bypass authentication and gain free access to its data‑streaming endpoints. The flaw does not grant any additional privileges beyond the ability to view or capture streamed media.

Affected Systems

The affected product is the UniFi Protect Application from Ubiquiti Inc. The advisory does not list specific affected versions, so current and future releases remain potentially impacted until an official fix is released.

Risk and Exploitability

The CVSS score of 8.6 indicates high severity, while an EPSS score of < 1 % shows exploitation is expected to be rare. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be network‑based; an attacker only needs access to the same network as the Protect system to reach the data‑streaming endpoints.

Generated by OpenCVE AI on July 21, 2026 at 11:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official vendor patch or firmware update from Ubiquiti when it becomes available.
  • Restrict network access to the UniFi Protect server using segmentation or firewall rules, allowing connections only from trusted management devices.
  • Disable or harden the data‑streaming APIs to require authenticated requests, implementing proper access controls in line with CWE‑284 guidelines.

Generated by OpenCVE AI on July 21, 2026 at 11:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 21 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title Improper Access Control in UniFi Protect Allows Unauthorized Data Streaming

Fri, 17 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Access Control Bypass in UniFi Protect Allows Unauthorized Data Streaming

Wed, 15 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Access Control Bypass in UniFi Protect Allows Unauthorized Data Streaming

Tue, 14 Jul 2026 17:00:00 +0000

Type Values Removed Values Added
Title Improper Access Control in UniFi Protect Allows Unauthorized Data Streaming

Mon, 13 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Improper Access Control in UniFi Protect Allows Unauthorized Data Streaming

Mon, 13 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Ubiquiti UniFi Protect Application Authentication Bypass Enabling Unauthorized Data Streaming

Sat, 11 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Ubiquiti UniFi Protect Application Authentication Bypass Enabling Unauthorized Data Streaming

Fri, 10 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Improper Access Control Bypass in UniFi Protect Data Streaming API

Thu, 09 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Title Improper Access Control Bypass in UniFi Protect Data Streaming API

Wed, 08 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Streaming via Improper Access Control in UniFi Protect

Tue, 07 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Streaming via Improper Access Control in UniFi Protect

Mon, 06 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Streaming via Improper Access Control in UniFi Protect Application

Sun, 05 Jul 2026 18:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Streaming via Improper Access Control in UniFi Protect Application

Sun, 05 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Video Streaming via Improper Access Control in Ubiquiti UniFi Protect

Sun, 05 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Video Streaming via Improper Access Control in Ubiquiti UniFi Protect

Sat, 04 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title UniFi Protect Authentication Bypass for Data Streaming

Sat, 04 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
Title UniFi Protect Authentication Bypass for Data Streaming

Sat, 04 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Title Network-Based Authentication Bypass Allowing Unauthorized Data Streaming

Fri, 03 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Network-Based Authentication Bypass Allowing Unauthorized Data Streaming

Fri, 03 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Title Improper Access Control Allows Network‑Based Authentication Bypass for UniFi Protect Data Streaming

Thu, 02 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title Improper Access Control Allows Network‑Based Authentication Bypass for UniFi Protect Data Streaming

Thu, 02 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Description A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect Application to bypass authentication for data streaming.
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2026-07-02T16:08:26.785Z

Reserved: 2026-06-13T15:00:00.605Z

Link: CVE-2026-54408

cve-icon Vulnrichment

Updated: 2026-07-02T16:08:24.220Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T11:30:06Z

Weaknesses