Junglewise Threat Intelligence

CVE-2026-77550: Ubiquiti UniFi OS CRLF injection authentication bypass

CVE-2026-77550 · Severity: critical · CVSS 10 · Published 2026-08-26

Technologies: Ubiquiti UniFi OS. Vendors: Ubiquiti.

Executive brief

UniFi OS is a network management platform used to control and monitor Ubiquiti networking devices. A CRLF (carriage return/line feed) injection vulnerability allows an attacker with network access to bypass authentication mechanisms, potentially gaining unauthorized administrative access to UniFi devices and the systems they protect.

Technical details

The vulnerability is an Improper Neutralization of CRLF Sequences (CWE-93) in UniFi OS that fails to properly sanitize input, allowing an attacker to inject carriage return and line feed characters to manipulate protocol-level behavior. An attacker with network access can craft malicious requests to bypass authentication controls without requiring valid credentials. This is a network-based attack vector that could lead to complete compromise of UniFi OS instances and downstream network infrastructure. A patch is expected from Ubiquiti; users should monitor the security advisory bulletin for available remediation.

Affected products

  • Ubiquiti UniFi OS

Timeline

  • 2026-08-26: disclosed

References

Related threats