HIGH 7.5

CVE-2026-54409: UniFi Protect Authentication Bypass Vulnerability (CVSS 7.5)

UniFi Protect cameras contain an authentication bypass vulnerability that could allow an attacker with network access to gain unauthorized control over the cameras. The flaw stems from improper initialization during the application startup process. An attacker would need to be on the network and satisfy certain conditions—including user interaction—to successfully exploit this weakness, making it moderately difficult but still a serious risk in environments where the attacker has already gained network-level access.

Source data · NVD / CISA · public domain

CVSS
3.1 · 7.5 HIGH · CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Weaknesses (CWE)
CWE-665
Affected products
1 configuration(s)
Published / Modified
2026-07-02 / 2026-07-07

NVD description (verbatim)

A malicious actor with access to the network and under certain conditions could exploit an Improper Initialization vulnerability found in UniFi Protect Application to bypass authentication in UniFi Protect Cameras.

1 reference(s) · View on NVD →

SEC.co analysis · AI-assisted, reviewed against source

Technical summary

CVE-2026-54409 is an Improper Initialization vulnerability (CWE-665) in Ubiquiti's UniFi Protect application affecting its camera authentication mechanisms. The vulnerability allows an unauthenticated attacker with network access to bypass authentication controls under specific conditions. The CVSS 3.1 score of 7.5 (HIGH) reflects a network-based attack vector with high complexity and user interaction requirements, but with severe impact across confidentiality, integrity, and availability. The improper initialization likely occurs during application lifecycle events where security-critical variables or state management are not properly established, leaving authentication checks in a vulnerable state during a narrow operational window.

Business impact

Successful exploitation could compromise the confidentiality, integrity, and availability of video surveillance data and camera operations. An attacker gaining unauthorized access to UniFi Protect cameras could view live or recorded footage, modify camera settings, disable recording, or pivot to other network systems. In organizations relying on UniFi Protect for security monitoring, this represents a direct threat to physical security situational awareness and potential compliance violations if customer or employee footage is accessed without authorization.

Affected systems

Ubiquiti UniFi Protect application and associated UniFi Protect cameras are affected. The exact range of affected versions has not been provided in the vulnerability advisory; consult Ubiquiti's official security bulletin to determine which firmware and application versions require patching. Environments running UniFi Protect for surveillance should assume vulnerability until patched versions are verified and deployed.

Exploitability

While the attack vector is network-based and requires no privileges, exploitation is constrained by high attack complexity and a requirement for user interaction. This means the attacker cannot execute a trivial, remote, unauthenticated attack; specific conditions and timing—possibly related to application restart, configuration change, or user login activity—must align. The vulnerability is not trivial to exploit but is feasible for a sophisticated threat actor already positioned on the network. It is not currently listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, suggesting active exploitation in the wild has not been widely documented as of the publication date.

Remediation

Apply security updates from Ubiquiti when they become available. Check Ubiquiti's official security advisories for the specific patched firmware and application versions. If patches are unavailable or cannot be deployed immediately, restrict network access to UniFi Protect systems using firewall rules, network segmentation, and access controls to limit exposure to trusted management networks. Disable remote access to cameras if not required and enforce strong authentication on all management interfaces.

Patch guidance

Verify the latest UniFi Protect application and camera firmware versions from Ubiquiti's official security bulletins and release notes. Deploy patches in a test environment first to ensure compatibility with your surveillance infrastructure. Prioritize patching in environments where UniFi Protect cameras are internet-facing or accessible from untrusted networks. Document patch deployment and re-test authentication workflows post-update to ensure proper operation.

Detection guidance

Monitor UniFi Protect application logs for unexpected authentication bypass events, failed authentication attempts followed by successful access, or anomalous camera configuration changes. Watch for access to UniFi Protect from unexpected network locations or IPs. Implement network segmentation to isolate UniFi Protect systems and monitor their traffic for suspicious patterns. Security information and event management (SIEM) systems should correlate authentication events with subsequent unauthorized activity on cameras. Review access logs for any sessions initiated during periods of application restart or configuration changes.

Why prioritize this

This vulnerability should be prioritized for organizations running UniFi Protect in security-critical roles. Although active exploitation is not yet documented in KEV, the high CVSS score, direct impact on physical security systems, and feasibility of exploitation by network-positioned attackers warrant timely patching. Organizations with internet-facing UniFi Protect systems or those in regulated environments (finance, healthcare, government) should treat this as elevated priority.

Risk score, explained

The CVSS 3.1 score of 7.5 (HIGH) reflects a network-accessible vulnerability with high impact across CIA triad but mitigated by high attack complexity and user interaction requirements. The lack of KEV listing suggests it is not yet publicly weaponized at scale. For organizations with strong network segmentation and limited attacker access, risk may be moderate; for those with flat networks or internet-exposed systems, risk is substantial. Risk should be assessed in the context of your network topology and the role UniFi Protect plays in your security posture.

Frequently asked questions

Does this vulnerability require the attacker to have valid credentials?

No. The vulnerability allows authentication bypass, meaning an unauthenticated attacker can exploit it. However, the attacker must already have network access and specific conditions (timing, user interaction, application state) must be met, so it is not a trivial unauthenticated remote code execution.

Can this vulnerability be exploited through the internet?

The attack vector is listed as Network (AV:N), meaning remote exploitation is theoretically possible. However, high attack complexity and user interaction requirements mean the attacker must satisfy specific conditions. If your UniFi Protect system is behind a firewall and not directly internet-exposed, your risk is lower, but internal threats remain a concern.

What should I do if I cannot patch immediately?

Implement network segmentation to restrict access to UniFi Protect management interfaces to trusted networks only. Use firewall rules to block unauthorized access, disable remote management if not required, and enforce strong passwords on all accounts. Monitor logs closely for suspicious activity and consider disconnecting non-critical cameras until patches are available.

Is there a workaround that fixes the vulnerability without patching?

No workaround has been published that eliminates the vulnerability. Only Ubiquiti's official security patches will resolve the underlying improper initialization flaw. Mitigation measures (network access controls, monitoring) reduce risk but do not eliminate the vulnerability itself.

This analysis is provided for informational purposes only and is based on publicly available vulnerability data current as of the publication date. Specific affected product versions, patch release dates, and detailed exploitation conditions should be verified against Ubiquiti's official security advisories before making remediation decisions. SEC.co does not provide warranty of accuracy regarding vendor patch timelines or product availability. Organizations should conduct their own risk assessments and consult with Ubiquiti support for deployment-specific guidance. This vulnerability analysis does not constitute legal, compliance, or security policy advice. Source: NVD (public-domain), retrieved 2026-08-11. Analysis generated by SEC.co (claude-haiku-4-5).