PT-2026-82085 · Ubiquiti · Unifi Talk Application
CVE-2026-77554
·
Published
2026-08-26
·
Updated
2026-08-28
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
UniFi Talk Application versions prior to 5.3.2
Description
An improper input validation flaw allows a malicious actor with network access to execute a command injection on the host device. This issue enables the execution of operating system commands without requiring prior authentication or user interaction, potentially leading to a full compromise of the host running the application. Ubiquiti has a global presence with nearly 85 million devices shipped across more than 200 countries and territories.
Recommendations
Update UniFi Talk Application to version 5.3.2 or later.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Unifi Talk Application