CVE-2026-55113: UI UniFi Talk Application

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

A malicious actor with access to the network could exploit a Server-Side Request Forgery (SSRF) vulnerability found in UniFi Talk Application to execute a Denial of Service (DoS) attack and bypass authentication in certain UniFi Talk API endpoints.

Affected products

  • UI UniFi Talk Application: before 5.2.2 (fixed in 5.2.2)

Published 2026-07-02. Last modified 2026-07-09.