CVE-2026-77550

UniFi: Improper Neutralization of CRLF Sequences ('CRLF Injection') (CVE-2026-77550)

criticalEPSS 0.8%

Affected

  • Ubiquiti/UniFi = OS..OS

Description

A malicious actor with access to the network could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices running UniFi OS to bypass authentication to such UniFi OS devices or instances.

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

UbiquitiUniFi
OS

Metrics

10.0
Source: cna-v3
55.3 %
High — this CVE ranks above the median of all CVEs scored today (rank ≥ 36%).
Show all metrics
Severity
critical
no public PoC known
0.8 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-08-26 11:16 UTC
CWE-93

Weakness classes (CWE)

  • CWE-93Base

    Improper Neutralization of CRLF Sequences ('CRLF Injection')

    The product uses CRLF (carriage return line feeds) as a special element, e.g. to separate lines or records, but it does not neutralize or incorrectly neutralizes CRLF sequences from inputs.

    cwe.mitre.org →

References & sources