Skip to content
Security Alerts

UniFi OS: 12 Vulnerabilities Including Authentication Bypass (CVE-2026-77550)

Ubiquiti published a bulletin covering 12 vulnerabilities in UniFi OS and UniFi applications. The most severe lets an attacker with network access bypass authentication on UniFi OS devices...

Summary

ParameterValue
CVE IDCVE-2026-77550 (primary) + 11 related
Alert SourceGitHub Advisory - Critical vulnerability
CVE Year2026
Publication Date2026-08-27
VendorUbiquiti
ProductUniFi OS and UniFi applications
CVSS Score10.0 (Critical) — highest in the bulletin
EPSS ScoreNo data for most; up to 1% for the oldest
CISA KEVNo
RansomwareNot confirmed

Consolidated entry. Ubiquiti disclosed 12 vulnerabilities at once, in a single bulletin. We cover them together because they affect the same platform and are removed by the same update — publishing twelve separate alerts would obscure the picture rather than clarify it.

Vulnerability Description

Source: NVD / Ubiquiti

Most severe: authentication bypass (CVSS 10.0)

CVE-2026-77550 — improper neutralization of CRLF sequences in certain devices running UniFi OS lets an attacker with network access bypass authentication to the device or instance. A score of 10.0 is the maximum on the CVSS scale.

CVE-2026-77549 (CVSS 9.0) — the same class of flaw (CRLF) leading to authentication bypass, under additional conditions.

Command execution on the device

  • CVE-2026-77554 (10.0) — command injection in the UniFi Talk application, via improper input validation.
  • CVE-2026-77552 (9.8) — command injection in the UniFi Enterprise Audio/Video Bridge.
  • CVE-2026-77539 and CVE-2026-77540 (both 9.1) — command injection on the host through UniFi OS Server; require high privileges.

Privilege escalation

  • CVE-2026-77553 (9.9) — UniFi Access: a low-privileged attacker escalates on the host device.
  • CVE-2026-77536 and CVE-2026-77534 (both 9.9) — improper access control in UniFi OS devices; escalation from low privileges.
  • CVE-2026-77557 (9.8) — UniFi Protect AI Key: privilege escalation on the device.
  • CVE-2026-77541 (9.1) — UniFi Network Application: escalation within the application, requires high privileges.
  • CVE-2026-77545 (9.0) — Active Debug Code left enabled in devices running UniFi OS.

Required Actions

  1. Update UniFi OS and every UniFi application in use (Network, Protect, Access, Talk) to the latest versions. Updating an application does not replace updating UniFi OS itself — these are separate components.
  2. Check whether the UniFi console is reachable from the internet. Remote management through Ubiquiti’s cloud does not require exposing the local interface.
  3. Pay particular attention to UniFi Access — this is a door access control system. Privilege escalation there means potential impact on physical security, not just network security.
  4. Verify that UniFi devices are in the asset inventory covered by your patching cycle. Network hardware tends to drop out of it, because “it works and nobody touches it”.

Who Is Affected?

The vulnerabilities affect devices running UniFi OS and the UniFi Network, Protect, Access and Talk applications from Ubiquiti.

UniFi is a widely adopted network platform in mid-size companies — access points, switches, gateways and management consoles. Beyond networking it also covers video surveillance (Protect), door access control (Access) and telephony (Talk).

That integration matters here: taking control of the UniFi platform in an organisation that uses it comprehensively grants simultaneous access to network infrastructure, camera recordings and the door-opening system. This bulletin deserves to be treated more seriously than a routine network hardware update.

Sources


Need help securing your systems? nFlo team offers vulnerability management and 24/7 SOC services. Contact us.

Learn More

Share:

Talk to an expert

Have questions about this topic? Get in touch with our specialist.

Sales Representative
Grzegorz Gnych

Grzegorz Gnych

Sales Representative

Response within 24 hours
Free consultation
Individual approach

Providing your phone number will speed up contact.

Want to Reduce IT Risk and Costs?

Book a free consultation - we respond within 24h

Response in 24h Free quote No obligations

Or download free guide:

Download NIS2 Checklist