CVE-2026-77554: Input Validation
Published Aug 26, 2026
·Updated
A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Talk Application to execute a Command Injection on the host device.
Affected Software
1 affected component
Ubiquiti UniFi Talk Application
Event History
Aug 26, 2026
CVE Published
via MITRE·10:45 AM
Data Sourced
via MITRE·10:45 AM
DescriptionSeverityWeakness
News Published
via BleepingComputer·01:17 PM
News Published
via BleepingComputer·01:19 PM
Frequently Asked Questions
1
Who can exploit this issue?
A malicious actor with network access can exploit it. No privileges or user interaction are required according to the supplied severity vector.
2
What is the potential impact if exploitation succeeds?
Successful exploitation can execute injected commands on the host device. The supplied vector indicates high impact to confidentiality, integrity, and availability, with scope changed.
3
Is there a workaround or affected-version information available?
The provided data does not include affected versions, fixed versions, configuration prerequisites, or mitigations. Consult the referenced security advisory for product-specific remediation details.