ZeroHour

CVE-2026-77550

mass

Authentication Bypass via CRLF Injection in Ubiquiti UniFi OS

CVSS 3.1
10.0 critical
EPSS
<1%p40
Published
()
Modified
AI analysis

CVE-2026-77550 is an Improper Neutralization of CRLF (carriage return/line feed) sequences (CWE-93) in certain devices running Ubiquiti's UniFi OS, rated CVSS 10.0 with network reachability, no privileges, and no user interaction required. An attacker who can reach the vulnerable UniFi OS device or instance over the network sends crafted input containing CR/LF sequences, which disrupts authentication processing and lets the attacker bypass login entirely. Successful exploitation yields complete administrative control of the console or instance, with high impact on confidentiality, integrity, and availability, and the scope change in the CVSS vector indicates impact can extend beyond the vulnerable component to protected resources behind it. Any organization running an affected UniFi OS device is exposed, with the greatest risk for consoles or instances reachable from untrusted networks. As of this analysis there is no known public proof-of-concept, the flaw is not in CISA's KEV, and EPSS puts near-term exploitation probability at about 0.5% (40th percentile); it is one of three 10.0-severity UniFi issues reported as fixed in recent updates.

What to do: Apply the latest UniFi OS firmware/update release from Ubiquiti, which includes the fixes for this and the other two 10.0 flaws in the same advisory batch. Until patched, restrict network access to UniFi OS management interfaces (e.g., firewall rules or VPN-only access) and avoid exposing consoles directly to the internet. Check internet-facing UniFi OS instances for exposure and monitor for vendor advisories identifying specific affected/fixed versions.

Affected
Ubiquiti UniFi OS (certain devices/instances)
Estimated exposure
massmillions of installed UniFi devices, with on the order of 100,000+ consoles/instances likely internet-exposed — Ubiquiti's UniFi line has a multi-million-device installed base per vendor deployment figures, and public internet scans (Shodan/Censys) index roughly 100,000+ exposed UniFi OS controllers/instances; exact affected-version coverage is not…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A malicious actor with access to the network could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices running UniFi OS to bypass authentication to such UniFi OS devices or instances.

Weakness
CWE-93
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

In the news

Three 10.0 security flaws fixed across Ubiquiti’s UniFi line

Ubiquiti patches 22 UniFi vulnerabilities, 21 rated critical including three CVSS 10.0 flaws enabling unauthorized access.

Ubiquiti disclosed and patched 22 vulnerabilities, 21 rated critical and three assigned the maximum CVSS 10.0 score: CVE-2026-77537, CVE-2026-77550, and CVE-2026-77554. All three involve improper access control that could let attackers gain privileges, while other flaws permit authentication bypass or arbitrary command execution. All but one of the 22 affect the UniFi product line. The company did not confirm whether any were exploited before patching.