Description

A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect Application to bypass authentication in certain UniFi Protect Application API endpoints.

Severity (CVSS)

Base score8.6
SeverityHigh
VersionCVSS 3.1
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
Provided byCNA

Weaknesses

  • CWE-284 — CWE-284 Improper Access Control - Generic

Affected products

VendorProductVersions
Ubiquiti IncUniFi Protect Application0 to <7.1.83

References

Authoritative sources

This page is a snapshot. For the latest enrichment and updates, view the record on CVE.org or the NVD.

Generated from the official CVE List on 03 Jul 2026 07:05 UTC.