CVE-2026-0826
Poly Voice – Possible Remote Control of Certain Poly Devices
9.2
CRITICAL
CVSS 4.0
EPSS 32.2% · 98th pctCWE-121
2026-06-01•Updated 2026-08-31
Description
In certain scenarios when the admin has enabled Interactive Connectivity Establishment (ICE), a buffer overflow could enable remote code execution on Poly Voice products on the Linux platform.
Severity
CVSS 4.0 · CNA9.2 CRITICAL
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:NSSVC · CISA-ADP
Exploitationnone
Automatableyes
Technical impacttotal
Affected Products
| Vendor | Product | Affected versions |
|---|---|---|
| HP Inc. | poly_trio_8300 | 0 to <8.1.7 |
| HP Inc. | poly_trio_8500 | 0 to <7.2.8 |
| HP Inc. | poly_trio_8800 | 0 to <7.2.8 |
| HP Inc. | poly_vvx | 0 to <6.4.8 |
References
1 LinksRecord Details
Published
2026-06-01
Last updated
2026-08-31
Assigner (CNA)
hp
Credited to
-
Related Tool Categories
Tool categories that test for or protect against this vulnerability class.
CWE-121 · Stack-based Buffer Overflow
CVE record data © The MITRE Corporation, used under the CVE Terms of Use. Exploited-in-the-wild data from the CISA Known Exploited Vulnerabilities catalog (CC0). Exploit prediction scores by FIRST EPSS (first.org/epss). This site is not endorsed or certified by MITRE, NVD, CISA, or FIRST.