Description
A malicious actor with access to the network and under certain conditions could exploit an Improper Initialization vulnerability found in UniFi Protect Application to bypass authentication in UniFi Protect Cameras.
Published: 2026-07-02
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an Improper Initialization flaw (CWE‑665) in the UniFi Protect Application that can allow an attacker who can reach the local network to send unauthenticated requests that leave the application in a state where it accepts those requests as legitimate. Once this state is achieved, an attacker gains unauthorized access to camera feeds or control functions, effectively bypassing authentication and compromising confidentiality, integrity, and availability of the surveillance system.

Affected Systems

The issue impacts Ubiquiti Inc’s UniFi Protect Application and any UniFi Protect Cameras that rely on that application for authentication. Because specific affected software versions are not listed, all current releases of the application and associated camera firmware should be treated as potentially vulnerable until a patch is applied.

Risk and Exploitability

With a CVSS score of 7.5 the vulnerability is considered high severity. The EPSS score of less than 1% indicates a very low but non‑zero likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be local or segment‑level network access, as the attacker must be able to send special unauthenticated requests to the Protect Application to trigger improper initialization. No publicly observed widespread exploitation is known, but the potential impact of local‑network credential bypass remains significant.

Generated by OpenCVE AI on July 22, 2026 at 13:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Ubiquiti firmware or UniFi Protect Application update that addresses the authentication bypass flaw by ensuring proper initialization to mitigate CWE‑665 Improper Initialization.
  • Segment camera devices on a dedicated VLAN and configure firewall rules to block unauthenticated traffic to Protect Application services, thereby preventing the state that could lead to the vulnerability.
  • Monitor network and camera logs for repeated or anomalous unauthenticated requests, and investigate any suspected exploitation attempts that could indicate improper initialization.

Generated by OpenCVE AI on July 22, 2026 at 13:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 22 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Title Improper Initialization in UniFi Protect Allows Authentication Bypass

Fri, 17 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Improper Initialization in UniFi Protect Allows Authentication Bypass

Wed, 15 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Title Improper Initialization in UniFi Protect Allows Authentication Bypass

Mon, 13 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Improper Initialization in UniFi Protect Allows Authentication Bypass

Mon, 13 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Authentication Bypass via Improper Initialization in UniFi Protect Application

Sun, 12 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title Authentication Bypass via Improper Initialization in UniFi Protect Application

Fri, 10 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Title Authentication Bypass via Improper Initialization in UniFi Protect Cameras

Thu, 09 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Authentication Bypass via Improper Initialization in UniFi Protect Cameras

Thu, 09 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Title Authentication Bypass via Improper Initialization in Ubiquiti UniFi Protect Application

Wed, 08 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Title Authentication Bypass via Improper Initialization in Ubiquiti UniFi Protect Application

Tue, 07 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
Title Pre‑authentication Bypass via Improper Initialization in UniFi Protect

Mon, 06 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Pre‑authentication Bypass via Improper Initialization in UniFi Protect

Mon, 06 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
Title Improper Initialization Enables Authentication Bypass in Ubiquiti UniFi Protect Cameras

Sun, 05 Jul 2026 18:00:00 +0000

Type Values Removed Values Added
Title Improper Initialization Enables Authentication Bypass in Ubiquiti UniFi Protect Cameras

Sun, 05 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Title Authentication Bypass in UniFi Protect Cameras via Improper Initialization

Sun, 05 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Title Authentication Bypass in UniFi Protect Cameras via Improper Initialization

Sat, 04 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Improper Initialization Allows Authentication Bypass in UniFi Protect Cameras

Fri, 03 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Improper Initialization Allows Authentication Bypass in UniFi Protect Cameras

Fri, 03 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Title UniFi Protect Camera Authentication Bypass via Improper Initialization

Thu, 02 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title UniFi Protect Camera Authentication Bypass via Improper Initialization

Thu, 02 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Description A malicious actor with access to the network and under certain conditions could exploit an Improper Initialization vulnerability found in UniFi Protect Application to bypass authentication in UniFi Protect Cameras.
Weaknesses CWE-665
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2026-07-02T16:10:07.537Z

Reserved: 2026-06-13T15:00:00.605Z

Link: CVE-2026-54409

cve-icon Vulnrichment

Updated: 2026-07-02T16:10:00.967Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-22T13:45:02Z

Weaknesses