Ghost in the Drone: Unauthenticated Shell Access in PX4 Autopilot’s 9.8 CVSS Nightmare
ID: e13c467c-59fe-5929-ab95-8e324a2f62c7
STIX ID: report--e13c467c-59fe-5929-ab95-8e324a2f62c7
Feed Name: securityonline.info
Threat Score
A critical CVE-2026-1579 advisory warns that PX4 Autopilot using MAVLink without message signing (default for many setups) permits unauthenticated sending of messages — including SERIAL_CONTROL — which can grant arbitrary shell access to the autopilot. With a CVSS score of 9.8, the flaw can enable attackers to take full control of drones; PX4 advises enabling MAVLink 2.0 message signing and following provided hardening documentation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
