Description
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect Application to bypass authentication in certain UniFi Protect Application API endpoints.
Severity (CVSS)
| Base score | 8.6 |
|---|---|
| Severity | High |
| Version | CVSS 3.1 |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H |
| Provided by | CNA |
Weaknesses
- CWE-284 — CWE-284 Improper Access Control - Generic
Affected products
| Vendor | Product | Versions |
|---|---|---|
| Ubiquiti Inc | UniFi Protect Application | 0 to <7.1.83 |
References
Generated from the official CVE List on 03 Jul 2026 07:05 UTC.