A malicious actor with access to the network could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices running UniFi OS to bypass authentication to such UniFi OS devices or instances.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 26 Aug 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 26 Aug 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | UniFi OS Authentication Bypass via CRLF Injection |
Wed, 26 Aug 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A malicious actor with access to the network could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices running UniFi OS to bypass authentication to such UniFi OS devices or instances. | |
| Weaknesses | CWE-93 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Ubiquiti
Published:
Updated: 2026-08-26T12:50:51.261Z
Reserved: 2026-08-20T20:32:37.794Z
Link: CVE-2026-77550
Updated: 2026-08-26T12:50:46.954Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-26T12:30:05Z
Weaknesses