Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-54408: UniFi Protect Application Authentication Bypass Risk
CVE-2026-54408
CVE-2026-54408
Summary
The UniFi Protect Application has a security weakness that allows an unauthorized person with access to the network to bypass the authentication process for data streaming. This means they could potentially access sensitive data without being authorized to do so. To protect your network, update the UniFi Protect Application to the latest version and ensure you have a strong password and proper network security in place.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| ubiquiti inc | unifi protect application | < 7.1.83 |
| ui | unifi_protect |
< 7.1.83 cpe:2.3:a:ui:unifi_protect:*:*:*:*:*:*:*:* |
Original title
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect Application to bypass authentication for data streaming.
Original description
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect Application to bypass authentication for data streaming.
nvd CVSS3.1
8.6
Vulnerability type
CWE-284
Improper Access Control
Published: 2 Jul 2026 · Updated: 20 Jul 2026 · First seen: 2 Jul 2026