Unauthorized Media Access in DJI Drones Affects Multiple Models
CVE-2026-78255

8.7HIGH

Key Information:

Vendor

Dji

Status
Neo
Neo 2
Flip
Air 3
Vendor
CVE Published:
24 August 2026

What is CVE-2026-78255?

A vulnerability exists in the HTTP media server of DJI drones where stored photos and videos are accessible via the /v2 endpoint without client authentication. This allows unauthorized users who can connect to the drone's internal network to systematically list and exfiltrate media files. The leaked materials can contain sensitive information such as private locations, personal identities, travel habits, and operational details of the drone users, leading to substantial privacy and security risks.

Affected Version(s)

Air 3 0 <= 01.00.1600,

Air 3S 0 <= 01.00.1400

Avata 2 0 <= 01.00.0400

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Abdelrahman Yousef
Dr. Jordan Samhi
.