← Vulnerability feed

Vulnerability record · CVE-2026-54407 · published 2 July 2026

CVE-2026-54407: Ui unifi protect improper access control vulnerability

Ui · Unifi Protect

A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect Application to bypass authentication in certain UniFi Protect Application API endpoints.

8.6 CVSS 3.1 High EPSS 0.45% · top 63.2% CWE-284 · Improper access control
8.6CVSS 3.1 base score
0.45%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
6 Jul 2026Last modified by NVD

Description

A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect Application to bypass authentication in certain UniFi Protect Application API endpoints.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-54407 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2026-55115Ui unifi protect server-side request forgery (ssrf) vulnerabilityA malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) in UniFi Protect Application to es…EPSS 0.47%9.8CVE-2026-54408Ui unifi protect improper access control vulnerabilityA malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect Application to bypass auth…EPSS 0.57%9.6CVE-2021-22943Ui unifi protect improper authentication vulnerabilityA vulnerability found in UniFi Protect application V1.18.1 and earlier permits a malicious actor who has already gained access to a network to subseq…EPSS 0.41%8.8CVE-2026-56841Ui unifi protect sql injection vulnerabilityA malicious actor with access to the network and low privileges could exploit an authenticated SQL Injection vulnerability found in UniFi Protect App…EPSS 0.49%8.8CVE-2026-21633Ui unifi protect improper authentication vulnerabilityA malicious actor with access to the adjacent network could obtain unauthorized access to a UniFi Protect Camera by exploiting a discovery protocol v…EPSS 0.45%8.8CVE-2021-22957Ui unifi protect vulnerabilityA Cross-Origin Resource Sharing (CORS) vulnerability found in UniFi Protect application Version 1.19.2 and earlier allows a malicious actor who has c…EPSS 0.91%8.1CVE-2026-54409Ui unifi protect vulnerabilityA malicious actor with access to the network and under certain conditions could exploit an Improper Initialization vulnerability found in UniFi Prote…EPSS 0.44%8.0CVE-2021-22944Ui unifi protect vulnerabilityA vulnerability found in UniFi Protect application V1.18.1 and earlier allows a malicious actor with a view-only role and network access to gain the …EPSS 0.42%

Source: NIST National Vulnerability Database (record CVE-2026-54407), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.