CVE-2026-86713
Awaiting Analysis Awaiting Analysis - Queue

Use-After-Free in PX4 Autopilot 1.17.0

Vulnerability report for CVE-2026-86713, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-08

Assigner: VulnCheck

Description

PX4 Autopilot through 1.17.0 contains a use-after-free vulnerability in the load_mon module's stop path where exit_and_cleanup() deletes the LoadMon object and frees the performance counter before perf_end() attempts to access it. Attackers can trigger this vulnerability by issuing the load_mon stop command from any PXH or MAVLink shell, causing reads and writes through freed memory that corrupt heap objects and destabilize the flight stack.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-08
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
px4 autopilot 1.17.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-416 The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

PX4 Autopilot through version 1.17.0 has a use-after-free vulnerability in the load_mon module. When the stop command is issued, the exit_and_cleanup() function deletes the LoadMon object and frees the performance counter before perf_end() can access it. This leads to memory corruption as reads and writes occur through freed memory, destabilizing the flight stack.

Detection Guidance

Detecting this vulnerability requires checking for the use-after-free condition in PX4 Autopilot versions up to 1.17.0. Monitor for crashes or instability after issuing the 'load_mon stop' command in PXH or MAVLink shells. Check system logs for heap corruption errors or unexpected memory access violations.

Impact Analysis

Attackers can exploit this flaw by sending the load_mon stop command via PXH or MAVLink shell. This causes heap corruption and may lead to system crashes, erratic behavior, or loss of control of the flight stack, potentially resulting in crashes or unsafe flight conditions.

Mitigation Strategies

Immediately upgrade PX4 Autopilot to a version beyond 1.17.0 where this issue is resolved. Avoid using the 'load_mon stop' command in PXH or MAVLink shells until patched. Monitor flight stack stability and apply any vendor-recommended patches or workarounds.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86713. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart