CVE-2026-26742: High severity PX4 Autopilot vulnerability
PX4 Autopilot versions 1.12.x through 1.15.x contain a protection mechanism failure in the "Re-arm Grace Period" logic. The system incorrectly applies the in-air emergency re-arm logic to ground scenarios. If a pilot switches to Manual mode and re-arms within 5 seconds (default configuration) of an automatic landing, the system bypasses all pre-flight safety checks, including the throttle threshold check. This allows for an immediate high-thrust takeoff if the throttle stick is raised, leading to loss of control.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-26742?
The severity of CVE-2026-26742 is considered moderate due to the potential for incorrect re-arm behavior in critical flight modes.
How do I fix CVE-2026-26742?
To mitigate CVE-2026-26742, update PX4 Autopilot to a version later than 1.15.x where the vulnerability is addressed.
Which versions are affected by CVE-2026-26742?
CVE-2026-26742 affects PX4 Autopilot versions 1.12.x through 1.15.x.
What are the consequences of CVE-2026-26742?
CVE-2026-26742 can result in incorrect application of emergency re-arm logic, potentially leading to unsafe operations during flight.
Is CVE-2026-26742 related to in-air operations?
Yes, CVE-2026-26742 involves a failure in the protection mechanism specifically concerning in-air emergency re-arm logic.