Access Control Weakness in Ghost Robotics Vision 60 Mobile App
CVE-2026-12990
7.7HIGH
What is CVE-2026-12990?
The mobile application for Ghost Robotics' Vision 60 robot is exposed to an access control vulnerability that permits multiple simultaneous sessions. This flaw allows an attacker with a modified app version to connect to the robot while a legitimate session is active, circumventing established control measures. As a result, the attacker can intercept sensitive data, including real-time video feeds, and interact with the system subtly, endangering operational security and confidentiality without alerting the legitimate user. Immediate action is advised to mitigate risks.
Affected Version(s)
Vision 60 5.5.0
References
CVSS V4
Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
VĂctor Manuel Charro GarcĂa, AdriĂĄn Campazas Vega and Claudia Ălvarez Aparicio.
