Null Pointer Dereference in PX4 Autopilot Affects Mission Control Safety
CVE-2026-86097

7.1HIGH

Key Information:

Vendor

Px4

Vendor
CVE Published:
4 September 2026

What is CVE-2026-86097?

The PX4 Autopilot software through version 1.17.0 has a null pointer dereference vulnerability in the param_set_default_file() and param_set_backup_file() functions. This flaw allows an attacker to crash the autopilot process by issuing 'param select' or 'param select-backup' commands without a path argument through any PX4 shell. This vulnerability poses a risk to mission control safety.

Affected Version(s)

PX4-Autopilot 0 <= 1.17.0

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Xiaoyang Chen
.