Account Pre-Hijacking Vulnerability in DroneAware by fduflyer
CVE-2026-48117

6.8MEDIUM

Key Information:

Vendor

Fduflyer

Vendor
CVE Published:
17 June 2026

What is CVE-2026-48117?

The DroneAware platform, a leading solution in drone detection, faced a vulnerability allowing attackers to hijack user accounts before completion of the account activation process. By registering an account with a victim's email and an attacker-controlled password, malicious actors could gain full access to the account once the legitimate user activated it. This vulnerability, while fully addressed server-side on May 20, 2025, underscores the importance of securing account processes to prevent unauthorized access and preserve user privacy. No client-side actions were necessary to mitigate the risk once the fix was implemented.

Affected Version(s)

DroneAware-Node-Releases < server-2026-05-20

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.