CVE-2026-21633

8.8

Ubiquiti Inc · UniFi Protect Application

A discovery protocol vulnerability in the UniFi Protect Application allows unauthenticated attackers on an adjacent network to gain unauthorized access to UniFi Protect cameras.

Executive summary

A critical vulnerability in the Ubiquiti UniFi Protect Application enables unauthorized access to camera systems by attackers on an adjacent network.

Vulnerability

The vulnerability exists within the discovery protocol of the UniFi Protect Application, allowing an unauthenticated attacker located on an adjacent network to bypass security controls and gain unauthorized access to camera devices.

Business impact

Successful exploitation of this flaw allows unauthorized actors to gain full control over surveillance cameras, leading to potential privacy breaches, unauthorized video monitoring, and potential lateral movement within the network. With a CVSS score of 8.8, this vulnerability represents a high risk to physical security and operational privacy, necessitating immediate attention to prevent unauthorized surveillance.

Remediation

Immediate Action: Update the UniFi Protect Application to version 6.2.72 or later immediately to resolve the vulnerable discovery protocol implementation.

Proactive Monitoring: Review system access logs for anomalous discovery requests or unauthorized connection attempts originating from the local network segment.

Compensating Controls: Restrict access to management interfaces and discovery protocols to trusted network segments using VLANs or firewall rules to prevent unauthorized adjacent network access.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the potential for complete compromise of camera systems, organizations must prioritize the application of the 6.2.72 update. Administrators should verify their current version and schedule maintenance windows to ensure all affected UniFi Protect instances are patched against this unauthorized access risk.

More Ubiquiti Inc CVEs

Sources