CVE-2025-23116: Ubiquiti Inc UniFi Protect Application

Critical severity, CVSS 9.6. EPSS: 0.5% chance of exploitation in the next 30 days.

An Authentication Bypass vulnerability on UniFi Protect Application with Auto-Adopt Bridge Devices enabled could allow a malicious actor with access to UniFi Protect Cameras adjacent network to take control of UniFi Protect Cameras.

Affected products

  • Ubiquiti Inc UniFi Protect Application: before 5.2.49 (fixed in 5.2.49)

Published 2025-03-01. Last modified 2026-06-17.