CVE-2026-26673: High severity DJI Mavic Mini vulnerability
Published Mar 4, 2026
·Updated
An issue in DJI Mavic Mini, Spark, Mavic Air, Mini, Mini SE 0.1.00.0500 and below allows a remote attacker to cause a denial of service via the DJI Enhanced-WiFi transmission subsystem
Affected Software
11 affected components
DJI Mavic Mini<=0.1.00.0500
DJI Spark<=0.1.00.0500
DJI Mavic Air<=0.1.00.0500
DJI Mini<=0.1.00.0500
DJI Mini SE<=0.1.00.0500
All of the following
DJI Mavic Mini Firmware<=01.00.0600
DJI Mavic Mini
All of the following
DJI Spark Firmware<=01.00.1000
DJI Spark
All of the following
DJI Mini Se Firmware<=01.02.0000
DJI Mini SE
Event History
Mar 4, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-26673?
CVE-2026-26673 is classified as a denial of service vulnerability affecting certain DJI drone models.
2
How do I fix CVE-2026-26673?
To fix CVE-2026-26673, update your affected DJI drone firmware to a version above 0.1.00.0500.
3
Which products are affected by CVE-2026-26673?
CVE-2026-26673 affects the DJI Mavic Mini, Spark, Mavic Air, Mini, and Mini SE models with firmware version 0.1.00.0500 and below.
4
Can CVE-2026-26673 be exploited remotely?
Yes, CVE-2026-26673 can be exploited remotely to cause a denial of service.
5
What impact does CVE-2026-26673 have on users?
CVE-2026-26673 can disrupt the operation of affected DJI drones, resulting in potential loss of control.