A critical authenticated SQL injection vulnerability has been identified in the UniFi Talk Application, affecting the appliance version. This vulnerability, designated CVE-2026-50747, carries a CVSS score of 9.9 and is classified as critical. An attacker with low privileges and network access could exploit this flaw to escalate privileges on the host device. The vulnerability arises from improper input validation in the application's database interactions. This poses a significant risk to organizations utilizing the affected software, as successful exploitation could lead to unauthorized access and control over the system. Immediate action is recommended to mitigate this risk. Users should apply the latest security patches provided by the vendor to address this vulnerability. Additionally, network segmentation and strict access controls should be enforced to limit potential attack surfaces. Organizations are advised to monitor for any suspicious activity and conduct regular security assessments to ensure their systems remain protected against such threats.