Logic Flaw in PX4 Autopilot Affecting Drone Control Mechanism
CVE-2026-26741
8.1HIGH
What is CVE-2026-26741?
The PX4 Autopilot, versions 1.12.x through 1.15.x, exhibits a significant logic flaw within its mode switching mechanism. This vulnerability occurs during the transition from Auto mode to Manual mode while the drone is in an 'ARMED' state. Specifically, the system fails to implement a critical throttle threshold safety check for the physical throttle stick. Consequently, this may lead to uncontrolled drone behavior, such as rapid ascent, posing risks of serious property damage and loss of control during operation.
