Account Pre-Hijacking Vulnerability in DroneAware by fduflyer
CVE-2026-48117
6.8MEDIUM
What is CVE-2026-48117?
The DroneAware platform, a leading solution in drone detection, faced a vulnerability allowing attackers to hijack user accounts before completion of the account activation process. By registering an account with a victim's email and an attacker-controlled password, malicious actors could gain full access to the account once the legitimate user activated it. This vulnerability, while fully addressed server-side on May 20, 2025, underscores the importance of securing account processes to prevent unauthorized access and preserve user privacy. No client-side actions were necessary to mitigate the risk once the fix was implemented.
Affected Version(s)
DroneAware-Node-Releases < server-2026-05-20
