PT-2026-29340 · Px4 · Autopilot

Dolev Aviv

·

Published

2026-03-31

·

Updated

2026-03-31

·

CVE-2026-1579

CVSS v3.1

9.8

Critical

AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The MAVLink communication protocol does not require cryptographic authentication by default. When MAVLink 2.0 message signing is not enabled, any message -- including SERIAL CONTROL, which provides interactive shell access -- can be sent by an unauthenticated party with access to the MAVLink interface. PX4 provides MAVLink 2.0 message signing as the cryptographic authentication mechanism for all MAVLink communication. When signing is enabled, unsigned messages are rejected at the protocol level.

Fix

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2026-1579

Affected Products

Autopilot