Description
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect Application to bypass authentication for data streaming.
Published: 2026-07-02
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an Improper Access Control (CWE‑284) flaw in the UniFi Protect Application that allows an attacker who can reach the device on the network to bypass authentication and directly access its data‑streaming endpoints. The flaw does not grant additional privileges beyond the ability to view or capture streamed media, yet the exposure of live or recorded footage can compromise privacy and operational security.

Affected Systems

The affected product is the UniFi Protect Application from Ubiquiti Inc. The advisory does not list specific affected versions, implying that all currently deployed releases may be vulnerable until a vendor patch is released.

Risk and Exploitability

The CVSS score of 8.6 indicates a high severity issue. The EPSS score of < 1 % suggests that exploitation is not frequently observed. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be network‑based; an attacker only needs to be on the same network as the Protect system to reach the data‑streaming endpoints and exploit the flaw.

Generated by OpenCVE AI on July 31, 2026 at 15:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official vendor patch for the UniFi Protect Application as soon as it is released.
  • Segregate the Protect server from the rest of the network by implementing VLANs or firewall rules that allow only management devices to reach the data‑streaming services.
  • Disable or restrict the data‑streaming APIs to require authenticated requests, following proper access control best practices for CWE‑284.

Generated by OpenCVE AI on July 31, 2026 at 15:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 31 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Title Improper Access Control Allows Network-Based Authentication Bypass for UniFi Protect Data Streaming

Sat, 25 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Title Improper Access Control in UniFi Protect Allows Unauthorized Data Streaming

Tue, 21 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title Improper Access Control in UniFi Protect Allows Unauthorized Data Streaming

Fri, 17 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Access Control Bypass in UniFi Protect Allows Unauthorized Data Streaming

Wed, 15 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Access Control Bypass in UniFi Protect Allows Unauthorized Data Streaming

Tue, 14 Jul 2026 17:00:00 +0000

Type Values Removed Values Added
Title Improper Access Control in UniFi Protect Allows Unauthorized Data Streaming

Mon, 13 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Improper Access Control in UniFi Protect Allows Unauthorized Data Streaming

Mon, 13 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Ubiquiti UniFi Protect Application Authentication Bypass Enabling Unauthorized Data Streaming

Sat, 11 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Ubiquiti UniFi Protect Application Authentication Bypass Enabling Unauthorized Data Streaming

Fri, 10 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Improper Access Control Bypass in UniFi Protect Data Streaming API

Thu, 09 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Title Improper Access Control Bypass in UniFi Protect Data Streaming API

Wed, 08 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Streaming via Improper Access Control in UniFi Protect

Tue, 07 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Streaming via Improper Access Control in UniFi Protect

Mon, 06 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Streaming via Improper Access Control in UniFi Protect Application

Sun, 05 Jul 2026 18:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Streaming via Improper Access Control in UniFi Protect Application

Sun, 05 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Video Streaming via Improper Access Control in Ubiquiti UniFi Protect

Sun, 05 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Video Streaming via Improper Access Control in Ubiquiti UniFi Protect

Sat, 04 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title UniFi Protect Authentication Bypass for Data Streaming

Sat, 04 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
Title UniFi Protect Authentication Bypass for Data Streaming

Sat, 04 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Title Network-Based Authentication Bypass Allowing Unauthorized Data Streaming

Fri, 03 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Network-Based Authentication Bypass Allowing Unauthorized Data Streaming

Fri, 03 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Title Improper Access Control Allows Network‑Based Authentication Bypass for UniFi Protect Data Streaming

Thu, 02 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title Improper Access Control Allows Network‑Based Authentication Bypass for UniFi Protect Data Streaming

Thu, 02 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Description A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect Application to bypass authentication for data streaming.
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L'}


Subscriptions

Ui Unifi Protect
cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2026-07-02T16:08:26.785Z

Reserved: 2026-06-13T15:00:00.605Z

Link: CVE-2026-54408

cve-icon Vulnrichment

Updated: 2026-07-02T16:08:24.220Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-02T15:17:04.523

Modified: 2026-07-07T16:33:15.573

Link: CVE-2026-54408

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T15:15:02Z

Weaknesses