Junglewise Threat Intelligence

CVE-2026-77554: Ubiquiti UniFi Talk command injection

CVE-2026-77554 · Severity: critical · CVSS 10 · Published 2026-08-26

Vendors: Ubiquiti.

Executive brief

UniFi Talk is a communication application used within Ubiquiti networks. A critical vulnerability allows an attacker with network access to inject arbitrary commands that execute on the host device, potentially compromising the entire system and any data processed by the application.

Technical details

An Improper Input Validation vulnerability in the UniFi Talk Application enables Command Injection attacks. The vulnerability requires network access to the affected device but does not require authentication. An attacker can send crafted network packets containing malicious command sequences that bypass input validation filters, resulting in arbitrary command execution with the privileges of the UniFi Talk process. This allows complete compromise of the host system.

Affected products

  • Ubiquiti UniFi Talk

Timeline

  • 2026-08-26: disclosed

References