Buffer Overflow Vulnerability in Poly Voice Products by HP
CVE-2026-0826
Key Information:
- Vendor
HP
- Vendor
- CVE Published:
- 1 June 2026
Badges
What is CVE-2026-0826?
CVE-2026-0826 represents a buffer overflow vulnerability found in Poly Voice products developed by HP. These products are primarily used for enterprise communication systems, facilitating voice and video calls over the internet. When the Interactive Connectivity Establishment (ICE) feature is enabled by the administrator, this vulnerability can be exploited, potentially allowing an attacker to execute arbitrary code remotely on systems running the affected Linux version of these products. This situation can severely jeopardize the integrity and availability of the organization's communication systems, leading to unauthorized access and manipulation of sensitive data.
Potential impact of CVE-2026-0826
-
Remote Code Execution: The most significant impact of this vulnerability is the ability for an attacker to execute arbitrary code remotely. This could lead to full system compromise, enabling an adversary to take control of the vulnerable Poly Voice products.
-
Data Breach Risks: Given that Poly Voice products are integral to enterprise communication, an exploit could facilitate unauthorized access to sensitive communications and data, increasing the risk of data breaches that could expose confidential business information or personal data of individuals.
-
Operational Disruption: The successful exploitation of this vulnerability may result in significant operational disruption. Malicious actors could manipulate communication services, potentially leading to downtime, loss of service integrity, and negatively impacting overall business operations.
Affected Version(s)
poly_trio_8300 Linux 0 < 8.1.7
poly_trio_8500 Linux 0 < 7.2.8
poly_trio_8800 Linux 0 < 7.2.8
News Articles
Critical Vulnerability in HP VoIP Phones Enables Enterprise Network Breaches
A stack-based buffer overflow vulnerability in HP VoIP phones allows remote attackers to execute arbitrary code with root privileges.
3 weeks ago
References
EPSS Score
26% chance of being exploited in the next 30 days.
CVSS V4
Timeline
- πΎ
Exploit known to exist
- π°
First article discovered by Securityweek
Vulnerability published
Vulnerability Reserved