Skip to content
CVSS 10.0CVSS 10.0 · CRITICAL

CVE-2026-77550Authentication bypass in UniFi OS via CRLF sequences

A malicious actor with access to the network could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices running UniFi OS to bypass authentication to such UniFi OS devices or instances.

View on NVD

Analysis

Un atacante con acceso a la red puede explotar una vulnerabilidad de secuencias CRLF para evadir por completo la autenticación en dispositivos e instancias con UniFi OS. Esta falla permite obtener acceso administrativo al sistema sin necesidad de credenciales válidas. Es fundamental actualizar cualquier consola o controlador de red afectado para evitar el compromiso total de la infraestructura.

Relevant roles

HardwareciberseguridadCloudLinux

Severity

Score: 10.0(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: CHANGED
C: HIGH
I: HIGH
A: HIGH
Weakness (CWE): CWE-93

EPSS

No EPSS score yet (CVE may be too fresh).

Technical description

A malicious actor with access to the network could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices running UniFi OS to bypass authentication to such UniFi OS devices or instances.

Published: 8/26/2026, 11:16:38 AM
Last modified: 8/27/2026, 4:16:50 AM

References

HomeEventsBlogResourcesCoursesTeam