UniFi OS CRLF injection — authentication bypass
A CVSS 10.0 CRLF injection vulnerability in Ubiquiti's UniFi OS allows unauthenticated remote attackers to bypass authentication. Affects UniFi OS devices; patch version not yet publicly documented.
- Vendor
- Ubiquiti
- Product
- UniFi OS (all devices running affected builds)
- CVSS
- 10.0
- EPSS (exploit probability)
- N/A
- Status
- patched
- Published
CVE-2026-77550 is a maximum-severity (CVSS 10.0) CRLF injection vulnerability in Ubiquiti’s UniFi OS — the underlying operating system running across UniFi network devices. Exploitation allows unauthenticated remote attackers to bypass authentication. The specific patched OS build version had not been publicly specified in initial disclosure; check the Ubiquiti security advisory bulletin for the definitive version requirement.
No known active exploitation at time of disclosure.
Check your UniFi OS console for available updates and apply the latest UniFi OS build immediately.
