HIGH 8.6

CVE-2026-54407: UniFi Protect Authentication Bypass (CVSS 8.6)

UniFi Protect Application contains an authentication bypass vulnerability that allows an attacker with network access to circumvent login controls on certain API endpoints. An unauthenticated attacker on the network can reach these endpoints and perform unauthorized actions without valid credentials, potentially affecting the confidentiality, integrity, and availability of protected systems.

Source data · NVD / CISA · public domain

CVSS
3.1 · 8.6 HIGH · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
Weaknesses (CWE)
CWE-284
Affected products
1 configuration(s)
Published / Modified
2026-07-02 / 2026-07-06

NVD description (verbatim)

A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect Application to bypass authentication in certain UniFi Protect Application API endpoints.

1 reference(s) · View on NVD →

SEC.co analysis · AI-assisted, reviewed against source

Technical summary

CVE-2026-54407 is an improper access control flaw (CWE-284) in UniFi Protect Application's API layer. The vulnerability permits an attacker with network connectivity to the affected application to bypass authentication mechanisms on specific API endpoints. The CVSS 3.1 vector (8.6 HIGH) reflects network-based attack feasibility with no authentication or user interaction required, resulting in partial confidentiality and integrity impact alongside high availability risk. The flaw does not require privilege escalation or special network positioning, making it straightforward to exploit once an attacker reaches the application.

Business impact

Authentication bypass on API endpoints creates significant operational risk. Attackers can access, modify, or disrupt protected video surveillance data and system configurations without credentials. For organizations relying on UniFi Protect for physical security monitoring, this vulnerability could enable unauthorized viewing of surveillance feeds, tampering with access logs, or system denial-of-service attacks. Regulatory compliance obligations (HIPAA, PCI-DSS, SOC 2) may be jeopardized if surveillance integrity cannot be guaranteed.

Affected systems

UniFi Protect Application by Ubiquiti Networks is affected. Verify your installed version against the vendor's security advisory to confirm whether your deployment is impacted. This applies regardless of deployment scale—from small office systems to large enterprise surveillance infrastructures.

Exploitability

Exploitation is straightforward: an attacker positioned on the network segment containing the UniFi Protect Application can directly call API endpoints without authentication. No special tools, user interaction, or privileged access is required. The attack surface includes any environment where the application is internet-facing or accessible from an untrusted network. Internal networks where threat actors have already established a foothold are equally vulnerable.

Remediation

Apply the vendor-supplied patch immediately upon availability. Verify the patch version against Ubiquiti's official security advisory. In the interim, implement network segmentation to restrict access to UniFi Protect Application APIs to trusted administrative networks only. Employ firewall rules, VPN enforcement, or layer-4 access controls to limit which hosts and subnets can reach the affected service.

Patch guidance

Consult Ubiquiti Networks' official security advisory for the specific patched version of UniFi Protect Application applicable to your deployment. Apply patches during a maintenance window to avoid surveillance service interruption. Test in a non-production environment first. After patching, verify API endpoints are no longer accessible without valid authentication by reviewing network logs and confirming failed authentication attempts are now blocked.

Detection guidance

Monitor UniFi Protect Application logs for API requests to sensitive endpoints (configuration, user management, video access) that lack valid authentication tokens or credentials. Look for repeated unauthenticated API calls from unexpected source IPs, particularly from external networks. Network-based detection should flag any traffic to the application's API port from hosts that are not known administrative clients. Check for unusual data access patterns or configuration changes that coincide with unrecognized login sessions.

Why prioritize this

This vulnerability merits immediate attention due to its HIGH CVSS score (8.6), network accessibility, zero authentication requirements, and direct impact on physical security infrastructure. Unlike vulnerabilities requiring local access or user interaction, this flaw can be exploited by any attacker with network reach. Surveillance system compromise carries both operational and compliance consequences. Although not yet on the Known Exploited Vulnerabilities (KEV) catalog, the ease of exploitation increases the likelihood of active abuse.

Risk score, explained

The CVSS 3.1 score of 8.6 reflects a HIGH severity rating driven by: (1) Network-based attack vector requiring no special positioning, (2) Low attack complexity—no privilege or authentication needed, (3) Partial confidentiality impact from unauthorized data access, (4) Partial integrity impact from potential configuration tampering, and (5) High availability risk if attackers disrupt the service. The combination of trivial exploit conditions and multi-faceted impact justifies the elevated score.

Frequently asked questions

Can this vulnerability be exploited remotely from the internet?

If UniFi Protect Application is internet-facing or accessible via a remote management solution, yes. However, the vulnerability fundamentally requires network connectivity to the application. In properly segmented internal networks where the application is not directly exposed, the risk is lower but not eliminated if an attacker gains internal network access through other means.

Do I need to authenticate to the UniFi Protect system to exploit this?

No. That is the core risk—the vulnerability allows attackers to bypass authentication entirely on certain API endpoints. A valid UniFi username and password are not required to exploit this flaw.

What should I prioritize: patching or network controls?

Both. Apply the patch immediately as the permanent fix. Deploy network segmentation and access controls in parallel to reduce exploit window risk. Do not assume network controls alone will indefinitely protect against this vulnerability—patch as soon as the vendor releases a fix.

Is this vulnerability being actively exploited?

As of the publication date, CVE-2026-54407 has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the ease of exploitation and surveillance data value make active exploitation likely; monitor threat intelligence feeds and vendor advisories for exploitation reports.

This analysis is based on vulnerability data published on 2026-07-02 and last modified 2026-07-06. Specific patch versions, affected version ranges, and detailed exploitation steps are available only from Ubiquiti Networks' official security advisory. Organizations should verify applicability of this vulnerability to their specific UniFi Protect deployment version and configuration. This explainer does not constitute security advice specific to your environment; consult your security team or a qualified security professional for remediation planning. No exploit code or weaponized proof-of-concept instructions are provided herein. Source: NVD (public-domain), retrieved 2026-08-11. Analysis generated by SEC.co (claude-haiku-4-5).