Description
A malicious actor with access to the network could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices running UniFi OS to bypass authentication to such UniFi OS devices or instances.
Published: 2026-08-26
Score: 10 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An attacker with network access to a UniFi OS device can craft a request containing special CRLF sequences that the system fails to neutralize properly. This allows the attacker to bypass authentication and gain unauthorized control of the device or the underlying instance. The flaw is an instance of Improper Neutralization of CRLF Sequences (CWE-93) and can compromise device integrity and availability.

Affected Systems

Vulnerable devices include Ubiquiti Cloud Gateways, Cloud Keys, Dream Machines, Dream Routers, Dream Wall, Enterprise Firewall Core, Enterprise Fortress Gateway, Enterprise Network Attached Storage, Enterprise Network Video Recorders, Express, Express 7, Network Attached Storage, Network Video Recorders, and UniFi OS Server. Version information is not presently available.

Risk and Exploitability

The CVSS score of 10 indicates critical severity. Although the EPSS score is not available, the lack of a KEV listing does not diminish the potential impact of this flaw. The attack vector is inferred to be network-based; an attacker must be able to reach the UniFi OS management interface, likely from a local network segment. The vulnerability can be exploited remotely by sending a crafted HTTP request to the device’s authentication endpoint, leading to authentication bypass.

Generated by OpenCVE AI on August 26, 2026 at 12:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the UniFi OS firmware to the latest version that contains the neutralization fix
  • Limit management access to the UniFi OS devices by restricting management ports to trusted IP ranges or VPN tunnels
  • Apply network segmentation and firewall rules to isolate management interfaces from general network traffic
  • If a patch is not available, implement temporary controls by blocking inbound CRLF injection patterns on the device’s web interface or blocking the affected management port from untrusted networks

Generated by OpenCVE AI on August 26, 2026 at 12:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Title UniFi OS Authentication Bypass via CRLF Injection

Wed, 26 Aug 2026 11:00:00 +0000

Type Values Removed Values Added
Description A malicious actor with access to the network could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices running UniFi OS to bypass authentication to such UniFi OS devices or instances.
Weaknesses CWE-93
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Ubiquiti

Published:

Updated: 2026-08-26T12:50:51.261Z

Reserved: 2026-08-20T20:32:37.794Z

Link: CVE-2026-77550

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T12:30:05Z

Weaknesses
  • CWE-93

    Improper Neutralization of CRLF Sequences ('CRLF Injection')