Description
A malicious actor with access to the network and under certain conditions could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices running UniFi OS to bypass authentication to such UniFi OS devices or instances.
Published: 2026-08-26
Score: 9 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an Improper Neutralization of CRLF sequences that allows an attacker to craft HTTP request headers containing CRLF injects. When processed by the UniFi OS authentication component, these malformed sequences can be used to bypass credentials and gain unauthorized access to the device's management interface. This results in loss of confidentiality and integrity of configuration and device state, and provides a foothold for further exploitation within the network.

Affected Systems

The affected products are Ubiquiti Inc devices running UniFi OS, including Cloud Gateways, Cloud Keys, Dream Machines, Dream Routers, Dream Wall, Enterprise Firewall Core, Enterprise Fortress Gateway, Enterprise Network Attached Storage, Enterprise Network Video Recorders, Express, Express 7, Network Attached Storage, Network Video Recorders, and the UniFi OS Server. Specific version details are not provided in the advisory.

Risk and Exploitability

The CVSS score of 9 indicates a high severity vulnerability. The EPSS score is not available, so the exact exploitation probability cannot be quantified. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a local network connection; an attacker with network access must be able to send crafted HTTP requests to an affected UniFi OS device to exploit the weakness. The potential impact is high, as bypassing authentication can lead to full administrative control of the device.

Generated by OpenCVE AI on August 26, 2026 at 12:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the UniFi OS firmware to the latest version that contains the CRLF injection fix as recommended by the vendor
  • Review network zoning and ensure that only trusted devices can reach the UniFi OS management interfaces
  • If re‑deployment of firmware is delayed, restrict access by placing the UniFi OS devices behind a firewall that blocks unsolicited HTTP/HTTPS traffic
  • Monitor device logs for failed authentication attempts and signs of CRLF injection patterns

Generated by OpenCVE AI on August 26, 2026 at 12:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 13:15:00 +0000

Type Values Removed Values Added
Title UniFi OS Improper CRLF Neutralization Enables Authentication Bypass

Wed, 26 Aug 2026 11:00:00 +0000

Type Values Removed Values Added
Description A malicious actor with access to the network and under certain conditions could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices running UniFi OS to bypass authentication to such UniFi OS devices or instances.
Weaknesses CWE-93
References
Metrics cvssV3_1

{'score': 9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Ubiquiti

Published:

Updated: 2026-08-26T12:51:19.756Z

Reserved: 2026-08-20T20:32:37.794Z

Link: CVE-2026-77549

cve-icon Vulnrichment

Updated: 2026-08-26T12:51:14.461Z

cve-icon NVD

Status : Received

Published: 2026-08-26T11:16:38.807

Modified: 2026-08-26T13:19:20.917

Link: CVE-2026-77549

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T13:00:05Z

Weaknesses
  • CWE-93

    Improper Neutralization of CRLF Sequences ('CRLF Injection')