Junglewise Threat Intelligence

CVE-2026-54408: Ubiquiti UniFi Protect auth bypass in data streaming

CVE-2026-54408 · Severity: high · CVSS 8.6 · Published 2026-07-02

Technologies: Ubiquiti UniFi Protect. Vendors: Ubiquiti Inc, Ubiquiti.

Executive brief

Ubiquiti UniFi Protect is a video surveillance management system used to monitor security cameras. A security flaw allows an unauthorized person on the network to bypass security checks and view live or recorded video streams without a password. This could lead to a significant privacy breach and unauthorized surveillance of protected premises.

Technical details

An improper access control vulnerability (CWE-284) exists in the Ubiquiti UniFi Protect Application prior to version 7.1.83. The flaw allows a remote, unauthenticated attacker with network access to the application to bypass authentication mechanisms specifically for data streaming services. By exploiting this, an attacker can gain unauthorized access to video feeds or other streamed data. The vulnerability is rated with a CVSS 3.1 score of 8.6, reflecting high confidentiality impact. Users are advised to update the UniFi Protect Application to version 7.1.83 or later to mitigate this risk.

Affected products

  • Ubiquiti Inc UniFi Protect Application < 7.1.83

Timeline

  • 2026-07-02: disclosed
  • 2026-07-02: advisory

References

Related threats