CVE-2026-54407

A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect Application to bypass authentication in certain UniFi Protect Application API endpoints.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ui:unifi_protect:*:*:*:*:*:*:*:*

History

06 Jul 2026, 19:32

Type Values Removed Values Added
References () https://community.ui.com/releases/Security-Advisory-Bulletin-066-066/984eceb3-49c8-4227-942d-671c289b3afc - () https://community.ui.com/releases/Security-Advisory-Bulletin-066-066/984eceb3-49c8-4227-942d-671c289b3afc - Vendor Advisory
First Time Ui
Ui unifi Protect
CPE cpe:2.3:a:ui:unifi_protect:*:*:*:*:*:*:*:*

02 Jul 2026, 15:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-02 15:17

Updated : 2026-07-06 19:32


NVD link : CVE-2026-54407

Mitre link : CVE-2026-54407

CVE.ORG link : CVE-2026-54407


JSON object : View

Products Affected

ui

  • unifi_protect
CWE
CWE-284

Improper Access Control