Use-After-Free Vulnerability in PX4 Autopilot Software by PX4
CVE-2026-86096

6MEDIUM

Key Information:

Vendor

Px4

Vendor
CVE Published:
4 September 2026

What is CVE-2026-86096?

The PX4 Autopilot software, up to version 1.17.0, is vulnerable to a use-after-free issue arising from a race condition in the TemperatureCalibration::start() function. This vulnerability allows attackers to exploit the calibration process through shell commands, leading to the potential for writing to freed heap memory. Such actions can corrupt unrelated data objects and compromise allocator metadata, which may destabilize heap operations within the software, making it susceptible to further attacks or system instability.

Affected Version(s)

PX4-Autopilot 0 <= 1.17.0

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Xiaoyang Chen
.