← Vulnerability feed

Vulnerability record · CVE-2026-54409 · published 2 July 2026

CVE-2026-54409: Ui unifi protect vulnerability

Ui · Unifi Protect

A malicious actor with access to the network and under certain conditions could exploit an Improper Initialization vulnerability found in UniFi Protect Application to bypass authentication in UniFi Protect Cameras.

8.1 CVSS 3.1 High EPSS 0.44% · top 64.3% CWE-665 · CWE-665
8.1CVSS 3.1 base score
0.44%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
7 Jul 2026Last modified by NVD

Description

A malicious actor with access to the network and under certain conditions could exploit an Improper Initialization vulnerability found in UniFi Protect Application to bypass authentication in UniFi Protect Cameras.

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-54409 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2026-55115Ui unifi protect server-side request forgery (ssrf) vulnerabilityA malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) in UniFi Protect Application to es…EPSS 0.47%9.8CVE-2026-54408Ui unifi protect improper access control vulnerabilityA malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect Application to bypass auth…EPSS 0.57%9.6CVE-2021-22943Ui unifi protect improper authentication vulnerabilityA vulnerability found in UniFi Protect application V1.18.1 and earlier permits a malicious actor who has already gained access to a network to subseq…EPSS 0.41%8.8CVE-2026-56841Ui unifi protect sql injection vulnerabilityA malicious actor with access to the network and low privileges could exploit an authenticated SQL Injection vulnerability found in UniFi Protect App…EPSS 0.49%8.8CVE-2026-21633Ui unifi protect improper authentication vulnerabilityA malicious actor with access to the adjacent network could obtain unauthorized access to a UniFi Protect Camera by exploiting a discovery protocol v…EPSS 0.45%8.8CVE-2021-22957Ui unifi protect vulnerabilityA Cross-Origin Resource Sharing (CORS) vulnerability found in UniFi Protect application Version 1.19.2 and earlier allows a malicious actor who has c…EPSS 0.91%8.6CVE-2026-54407Ui unifi protect improper access control vulnerabilityA malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect Application to bypass auth…EPSS 0.45%8.0CVE-2021-22944Ui unifi protect vulnerabilityA vulnerability found in UniFi Protect application V1.18.1 and earlier allows a malicious actor with a view-only role and network access to gain the …EPSS 0.42%

Source: NIST National Vulnerability Database (record CVE-2026-54409), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.