PT-2026-24381 · Unknown · Px4-Autopilot
Npuwyw
·
Published
2026-03-10
·
Updated
2026-03-23
·
CVE-2026-26741
CVSS v3.1
8.1
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
PX4 Autopilot versions 1.12.x through 1.15.x
Description
The autopilot software contains a logic flaw in the mode switching mechanism. Specifically, when transitioning from Auto mode to Manual mode while the drone is in the "ARMED" state – after landing and before the automatic disarm triggered by the
COM DISARM LAND parameter – a safety check for the physical throttle stick is missing. This can lead to loss of control, rapid uncontrolled ascent (flyaway), and potential property damage.Recommendations
Versions 1.12.x through 1.15.x should be updated when a fix is available.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Px4-Autopilot