Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
10.0
CVE-2026-77550: UniFi OS devices let network attacker skip login
CVE-2026-77550 · published 8 days ago
Summary
Some UniFi OS devices can be tricked by a user on the same network to bypass the login screen. This means an attacker could gain access without proper credentials. Apply the latest firmware updates from the vendor to close the gap.
What to do
- Update ubiquiti inc unifi os server to version 5.1.37 or later.
- Update ubiquiti inc cloud keys to version 5.1.31 or later.
- Update ubiquiti inc network video recorders to version 5.1.31 or later.
- Update ubiquiti inc enterprise network video recorders to version 5.1.31 or later.
- Update ubiquiti inc enterprise network attached storage to version 5.1.31 or later.
- Update ubiquiti inc dream machines to version 5.1.31 or later.
- Update ubiquiti inc enterprise firewall core to version 5.1.31 or later.
- Update ubiquiti inc dream routers to version 5.1.31 or later.
- Update ubiquiti inc enterprise fortress gateway to version 5.1.31 or later.
- Update ubiquiti inc cloud gateways to version 5.1.31 or later.
- Update ubiquiti inc dream wall to version 5.1.31 or later.
- Update ubiquiti inc express 7 to version 5.1.31 or later.
- Update ubiquiti inc network attached storage to version 5.1.32 or later.
- Update ubiquiti inc express to version 4.0.17 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| ubiquiti inc | unifi os server | < 5.1.37 |
| ubiquiti inc | cloud keys | < 5.1.31 |
| ubiquiti inc | network video recorders | < 5.1.31 |
| ubiquiti inc | enterprise network video recorders | < 5.1.31 |
| ubiquiti inc | enterprise network attached storage | < 5.1.31 |
| ubiquiti inc | dream machines | < 5.1.31 |
| ubiquiti inc | enterprise firewall core | < 5.1.31 |
| ubiquiti inc | dream routers | < 5.1.31 |
| ubiquiti inc | enterprise fortress gateway | < 5.1.31 |
| ubiquiti inc | cloud gateways | < 5.1.31 |
| ubiquiti inc | dream wall | < 5.1.31 |
| ubiquiti inc | express 7 | < 5.1.31 |
| ubiquiti inc | network attached storage | < 5.1.32 |
| ubiquiti inc | express | < 4.0.17 |
Original advisory text
A malicious actor with access to the network could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices running UniFi OS to bypass authentication to such UniF...
A malicious actor with access to the network could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices running UniFi OS to bypass authentication to such UniFi OS devices or instances.
Severity
10.0
Critical
CVSS 3.1: 10.0 (MITRE)
Exploitation
EPSS <1%
Type
CWE-93Improper Neutralization of CRLF Sequences ('CRLF Injection')
Timeline
Published26 Aug 2026
Updated3 Sep 2026
First seen26 Aug 2026
Monitor software like this
Free during beta