Access Control Weakness in Ghost Robotics Vision 60 Mobile App
CVE-2026-12990

7.7HIGH

Key Information:

Status
Vendor
CVE Published:
27 July 2026

What is CVE-2026-12990?

The mobile application for Ghost Robotics' Vision 60 robot is exposed to an access control vulnerability that permits multiple simultaneous sessions. This flaw allows an attacker with a modified app version to connect to the robot while a legitimate session is active, circumventing established control measures. As a result, the attacker can intercept sensitive data, including real-time video feeds, and interact with the system subtly, endangering operational security and confidentiality without alerting the legitimate user. Immediate action is advised to mitigate risks.

Affected Version(s)

Vision 60 5.5.0

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Víctor Manuel Charro García, Adriån Campazas Vega and Claudia Álvarez Aparicio.
.