CVE-2026-0826: Poly Voice – Possible Remote Control of Certain Poly Devices
In certain scenarios when the admin has enabled Interactive Connectivity Establishment (ICE), a buffer overflow could enable remote code execution on Poly Voice products on the Linux platform.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
If you are using Poly Voice on Linux, disable Interactive Connectivity Establishment (ICE) (in environments where ICE is enabled) to reduce the risk of remote code execution caused by the described buffer overflow.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0826?
CVE-2026-0826 has a severity rating of critical with a CVSS score of 9.2.
How do I fix CVE-2026-0826?
To mitigate CVE-2026-0826, ensure that Interactive Connectivity Establishment (ICE) is disabled on vulnerable Poly Voice products.
What devices are affected by CVE-2026-0826?
CVE-2026-0826 affects certain Poly Voice products running on the Linux platform.
What type of vulnerability is CVE-2026-0826?
CVE-2026-0826 is classified as a buffer overflow vulnerability.
What can happen if CVE-2026-0826 is exploited?
Exploitation of CVE-2026-0826 may allow an attacker to execute remote code on the affected Poly Voice devices.