CVE-2026-54407: High severity Ubiquiti Unifi Protect Application vulnerability
Published Jul 2, 2026
·Updated
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect Application to bypass authentication in certain UniFi Protect Application API endpoints.
Affected Software
2 affected components
Ubiquiti Unifi Protect Application
UI Unifi Protect<7.1.83
Event History
Jul 2, 2026
CVE Published
via MITRE·02:49 PM
Data Sourced
via MITRE·02:49 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-54407?
The severity of CVE-2026-54407 is high, with a CVSS score of 8.6.
2
How do I fix CVE-2026-54407?
To mitigate CVE-2026-54407, update the UniFi Protect Application to the latest version as specified by Ubiquiti.
3
What are the potential impacts of CVE-2026-54407?
CVE-2026-54407 can allow a malicious actor to bypass authentication and gain unauthorized access to certain API endpoints.
4
Who is affected by CVE-2026-54407?
CVE-2026-54407 affects users of the Ubiquiti UniFi Protect Application that have network access.
5
When was CVE-2026-54407 published?
CVE-2026-54407 was published on July 2, 2026.