Impact
The vulnerability is an Improper Access Control (CWE‑284) flaw in the UniFi Protect Application that allows an attacker who can reach the device on the network to bypass authentication and directly access its data‑streaming endpoints. The flaw does not grant additional privileges beyond the ability to view or capture streamed media, yet the exposure of live or recorded footage can compromise privacy and operational security.
Affected Systems
The affected product is the UniFi Protect Application from Ubiquiti Inc. The advisory does not list specific affected versions, implying that all currently deployed releases may be vulnerable until a vendor patch is released.
Risk and Exploitability
The CVSS score of 8.6 indicates a high severity issue. The EPSS score of < 1 % suggests that exploitation is not frequently observed. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be network‑based; an attacker only needs to be on the same network as the Protect system to reach the data‑streaming endpoints and exploit the flaw.
OpenCVE Enrichment