Executive brief
Ubiquiti UniFi Talk is a business communication application used for managing VoIP phone systems. A security vulnerability allows an attacker with low-level access to the network to gain full administrative control over the host device. This could lead to the theft of sensitive communication data, disruption of phone services, or further unauthorized access to the corporate network.
Technical details
The UniFi Talk Application is vulnerable to multiple authenticated SQL injection flaws (CWE-89). An attacker with valid low-privileged credentials can send specially crafted network requests to the application to execute arbitrary SQL commands. This vulnerability allows for privilege escalation from a standard user to a system administrator on the underlying host device. The issue is fixed in UniFi Talk Application version 5.2.2 and later. The exploit requires network connectivity and valid low-privilege authentication but no user interaction.
Affected products
- Ubiquiti Inc UniFi Talk Application < 5.2.2
Timeline
- 2026-07-02: disclosed
- 2026-07-02: advisory