PT-2026-82085 · Ubiquiti · Unifi Talk Application

CVE-2026-77554

·

Published

2026-08-26

·

Updated

2026-08-28

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions UniFi Talk Application versions prior to 5.3.2
Description An improper input validation flaw allows a malicious actor with network access to execute a command injection on the host device. This issue enables the execution of operating system commands without requiring prior authentication or user interaction, potentially leading to a full compromise of the host running the application. Ubiquiti has a global presence with nearly 85 million devices shipped across more than 200 countries and territories.
Recommendations Update UniFi Talk Application to version 5.3.2 or later.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77554

Affected Products

Unifi Talk Application