Executive brief
A security vulnerability in the UniFi Protect Application could allow an unauthorized person on the network to bypass security controls on UniFi Protect Cameras. This application is used to manage and monitor security camera systems; an exploit could allow an attacker to gain unauthorized access to camera feeds or settings. This could lead to a significant breach of physical security and privacy for organizations using these surveillance systems.
Technical details
An Improper Initialization vulnerability (CWE-665) exists in the Ubiquiti UniFi Protect Application prior to version 7.1.83. A network-based attacker could exploit this flaw under specific conditions to bypass authentication mechanisms on connected UniFi Protect Cameras. The attack requires high complexity and some level of user interaction, as indicated by the CVSS vector. Successful exploitation grants the attacker unauthorized access to the camera hardware, potentially allowing for unauthorized viewing or configuration changes. Users are advised to update the UniFi Protect Application to version 7.1.83 or later to mitigate this risk.
Affected products
- Ubiquiti Inc UniFi Protect Application < 7.1.83
Timeline
- 2026-07-02: disclosed
- 2026-07-02: advisory