PT-2026-24382 · Unknown · Px4-Autopilot

Npuwyw

·

Published

2026-03-10

·

Updated

2026-03-23

·

CVE-2026-26742

CVSS v3.1

8.1

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions PX4 Autopilot versions 1.12.x through 1.15.x
Description The software contains a flaw in the protection mechanism within the 'Re-arm Grace Period' logic. The system incorrectly applies in-air emergency re-arm logic to ground scenarios. Switching to Manual mode and re-arming within 5 seconds of an automatic landing bypasses pre-flight safety checks, including the throttle threshold check. This allows for immediate high-thrust takeoff if the throttle stick is raised, potentially leading to loss of control.
Recommendations Versions 1.12.x through 1.15.x: Avoid switching to Manual mode and re-arming within 5 seconds after an automatic landing.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-26742

Affected Products

Px4-Autopilot