Description
A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found in UniFi Talk Application to escalate privileges on the host device.
Published: 2026-07-02
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability centers flaws in the UniFi Talk Application, enabling an attacker with network access and low‑privilege credentials to craft malicious SQL statements. These injection points can be used to elevate the attacker’s privileges on the host device, giving them broader control over the system and potentially its network environment. The weakness corresponds to CWE‑89. No explicit coverage of remote code execution, data diversion, or denial of service is stated in the vendor’s advisory.

Affected Systems

The flaw affects Ubiquiti Inc's UniFi Talk Application. All installed instances could be vulnerable in the absence of explicit version exclusions. Affected version information is not provided in the advisory, so administrators should assume every deployed copy may be impacted until a patch is applied.

Risk and Exploitability

The CVSS issue in the Critical severity range. The EPSS score is <1%, and the vulnerability is not listed in the CISA KEV catalog, indicating no known public exploits yet. The attack requires network connectivity and prior access to authenticated low‑privilege credentials; the likely attack vector is thus a network‑based manipulate the application’s SQL queries. Because the exploitation path demands legitimate credentials, the risk is higher in environments that expose the device to untrusted devices or fail to enforce strict account hygiene. No mention of exploitation without prior information is provided.

Generated by OpenCVE AI on July 21, 2026 at 11:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Patch or upgrade to the latest UniFi Talk Application release as described by Ubiquiti in their security advisory.
  • Enforce the principle of least privilege by removing or limiting accounts that have unnecessary local access to the application before applying the patch.
  • Restrict external access to the device via network segmentation and firewall rules, ensuring only trusted networks can reach the application’s interfaces.
  • Configure the application’s database connection‑default credentials.

Generated by OpenCVE AI on July 21, 2026 at 11:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 21 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title SQL Injection Vulnerability Allowing Privilege Escalation in Ubiquiti UniFi Talk Application

Wed, 15 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title SQL Injection Vulnerability Allowing Privilege Escalation in Ubiquiti UniFi Talk Application

Tue, 14 Jul 2026 17:00:00 +0000

Type Values Removed Values Added
Title Authenticated SQL Injection in UniFi Talk Enabling Privilege Escalation

Mon, 13 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Authenticated SQL Injection in UniFi Talk Enabling Privilege Escalation

Mon, 13 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Authenticated SQL Injection Enables Privilege Escalation in UniFi Talk Application

Sat, 11 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Authenticated SQL Injection Enables Privilege Escalation in UniFi Talk Application

Fri, 10 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Authenticated SQL Injection Enables Privilege Escalation in UniFi Talk

Thu, 09 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Title Authenticated SQL Injection Enables Privilege Escalation in UniFi Talk

Wed, 08 Jul 2026 18:00:00 +0000

Type Values Removed Values Added
Title Elevated Privileges via Authenticated SQL Injection in UniFi Talk Application

Tue, 07 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title Elevated Privileges via Authenticated SQL Injection in UniFi Talk Application

Mon, 06 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title Authenticated SQL Injection Enables Privilege Escalation in UniFi Talk

Mon, 06 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Title Authenticated SQL Injection Enables Privilege Escalation in UniFi Talk

Sun, 05 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title Authenticated SQL Injection in UniFi Talk Allows Privilege Escalation

Sun, 05 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Title Authenticated SQL Injection in UniFi Talk Allows Privilege Escalation

Sun, 05 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Authenticated SQL Injection in UniFi Talk Application

Sat, 04 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Authenticated SQL Injection in UniFi Talk Application

Sat, 04 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Authenticated SQL Injection in UniFi Talk Application

Sat, 04 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Authenticated SQL Injection in UniFi Talk Application

Fri, 03 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Multiple Authenticated SQL Injection Vulnerabilities in UniFi Talk Enabling Privilege Escalation

Fri, 03 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
Title Multiple Authenticated SQL Injection Vulnerabilities in UniFi Talk Enabling Privilege Escalation

Thu, 02 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Description A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found in UniFi Talk Application to escalate privileges on the host device.
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2026-07-02T15:52:10.116Z

Reserved: 2026-06-06T15:00:09.780Z

Link: CVE-2026-50747

cve-icon Vulnrichment

Updated: 2026-07-02T15:41:34.962Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T11:15:05Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')