CVE-2026-12990
Received Received - Intake

Access Control Bypass in Ghost Robotics Vision 60 Mobile App

Vulnerability report for CVE-2026-12990, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-27

Last updated on: 2026-07-27

Assigner: Spanish National Cybersecurity Institute, S.A. (INCIBE)

Description

An access control vulnerability in the mobile app (APK v5.5.0) for Ghost Robotics' Vision 60 robot allows multiple simultaneous sessions to run without proper client validation or session integrity checks. An attacker with a modified version of the app can connect to the robot during an active, legitimate session. This allows the attacker to bypass control restrictions, intercept sensitive information (such as real-time video), and partially interact with the system unnoticed and without disconnecting the legitimate user, compromising confidentiality and operational security.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-27
Last Modified
2026-07-27
Generated
2026-07-27
AI Q&A
2026-07-27
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ghost_robotics vision_60 5.5.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an access control issue in Ghost Robotics' Vision 60 robot's mobile app (APK v5.5.0). It allows multiple simultaneous sessions without proper validation, letting an attacker with a modified app connect during an active legitimate session. This bypasses controls, intercepts sensitive data like real-time video, and interacts with the system without disconnecting the legitimate user.

Detection Guidance

Detection of this vulnerability requires monitoring for unauthorized or duplicate sessions on the Ghost Robotics Vision 60 robot's mobile app interface. Check for multiple active connections from the same user account or device, especially if the legitimate session remains active while an unknown session is present. Inspect network traffic for unexpected data exfiltration or command interactions.

Impact Analysis

An attacker could access sensitive information such as real-time video feeds, bypass security controls, and interact with the robot without detection. This compromises confidentiality and operational security, potentially leading to unauthorized actions or data breaches.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR (data protection) and HIPAA (health information privacy) requirements. Non-compliance may result in legal penalties, reputational damage, and loss of trust.

Mitigation Strategies

Immediately update the Ghost Robotics Vision 60 mobile app to the latest version to ensure proper session validation. Disable any modified or unofficial versions of the app. Monitor network traffic for unauthorized connections to the robot during active sessions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-12990. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart