CVE-2026-26742
Received Received - Intake
Bypass of Pre-Flight Checks in PX4 Autopilot Causes Control Loss

Publication date: 2026-03-10

Last updated on: 2026-03-12

Assigner: MITRE

Description
PX4 Autopilot versions 1.12.x through 1.15.x contain a protection mechanism failure in the "Re-arm Grace Period" logic. The system incorrectly applies the in-air emergency re-arm logic to ground scenarios. If a pilot switches to Manual mode and re-arms within 5 seconds (default configuration) of an automatic landing, the system bypasses all pre-flight safety checks, including the throttle threshold check. This allows for an immediate high-thrust takeoff if the throttle stick is raised, leading to loss of control.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-03-10
Last Modified
2026-03-12
Generated
2026-06-16
AI Q&A
2026-03-10
EPSS Evaluated
2026-06-15
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
dronecode px4_drone_autopilot From 1.12.0 (inc) to 1.16.0 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

The vulnerability exists in PX4 Autopilot versions 1.12.x through 1.15.x in the "Re-arm Grace Period" logic. The system mistakenly applies the in-air emergency re-arm logic to situations on the ground. Specifically, if a pilot switches to Manual mode and re-arms the system within 5 seconds after an automatic landing, the system bypasses all pre-flight safety checks, including the throttle threshold check.

This flaw allows an immediate high-thrust takeoff if the throttle stick is raised, which can lead to loss of control of the vehicle.

Impact Analysis

This vulnerability can lead to a dangerous situation where the vehicle takes off immediately with high thrust without proper safety checks. This can cause loss of control, potentially resulting in crashes, damage to property, injury, or even loss of life depending on the context in which the PX4 Autopilot is used.

Compliance Impact

I don't know

Detection Guidance

I don't know

Mitigation Strategies

I don't know

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-26742. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart