Junglewise Threat Intelligence

CVE-2026-54407: Ubiquiti UniFi Protect authentication bypass in API endpoints

CVE-2026-54407 · Severity: high · CVSS 8.6 · Published 2026-07-02

Technologies: Ubiquiti UniFi Protect Application. Vendors: Ubiquiti Inc, Ubiquiti.

Executive brief

Ubiquiti UniFi Protect is a video surveillance management system used to monitor and record security camera footage. A security flaw in this application allows an unauthorized person on the network to bypass security checks and access certain internal functions. This could lead to unauthorized viewing of data, system changes, or a disruption of the surveillance service.

Technical details

An Improper Access Control vulnerability (CWE-284) exists in the Ubiquiti UniFi Protect Application prior to version 7.1.83. The flaw resides in certain API endpoints that fail to properly enforce authentication requirements. A remote, unauthenticated attacker with network access to the application can exploit this to bypass security controls. Successful exploitation could allow the attacker to read sensitive information, modify settings, or cause a denial-of-service condition. The issue is resolved in UniFi Protect Application version 7.1.83 and later.

Affected products

  • Ubiquiti Inc UniFi Protect Application < 7.1.83

Timeline

  • 2026-07-02: advisory
  • 2026-07-02: disclosed

References

Related threats