Ubiquiti UniFi Protect Application Access Token Misconfiguration Vulnerability

Vulnerability

A misconfigured access token mechanism in the UniFi Protect Application, versions through 5.3.41, could allow recipients of a 'Share Livestream' link to retain access to the livestream even after the link has been disabled.

Impact

Exploitation of this vulnerability could lead to unauthorized access to livestreams that should have been disabled.

Remediation

Users are advised to update the UniFi Protect Application to version 5.3.45 or later.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.0
exploitability
4.8
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.