Vulnerability Details CVE-2026-26742
PX4 Autopilot versions 1.12.x through 1.15.x contain a protection mechanism failure in the "Re-arm Grace Period" logic. The system incorrectly applies the in-air emergency re-arm logic to ground scenarios. If a pilot switches to Manual mode and re-arms within 5 seconds (default configuration) of an automatic landing, the system bypasses all pre-flight safety checks, including the throttle threshold check. This allows for an immediate high-thrust takeoff if the throttle stick is raised, leading to loss of control.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 12.2%
CVSS Severity
CVSS v3 Score 8.1
Products affected by CVE-2026-26742
-
cpe:2.3:a:dronecode:px4_drone_autopilot:1.12.0
-
cpe:2.3:a:dronecode:px4_drone_autopilot:1.12.1
-
cpe:2.3:a:dronecode:px4_drone_autopilot:1.12.2
-
cpe:2.3:a:dronecode:px4_drone_autopilot:1.12.3
-
cpe:2.3:a:dronecode:px4_drone_autopilot:1.13.0
-
cpe:2.3:a:dronecode:px4_drone_autopilot:1.13.1
-
cpe:2.3:a:dronecode:px4_drone_autopilot:1.13.2
-
cpe:2.3:a:dronecode:px4_drone_autopilot:1.13.3
-
cpe:2.3:a:dronecode:px4_drone_autopilot:1.14.0
-
cpe:2.3:a:dronecode:px4_drone_autopilot:1.14.1
-
cpe:2.3:a:dronecode:px4_drone_autopilot:1.14.2
-
cpe:2.3:a:dronecode:px4_drone_autopilot:1.14.3
-
cpe:2.3:a:dronecode:px4_drone_autopilot:1.14.4
-
cpe:2.3:a:dronecode:px4_drone_autopilot:1.15.0
-
cpe:2.3:a:dronecode:px4_drone_autopilot:1.15.1
-
cpe:2.3:a:dronecode:px4_drone_autopilot:1.15.2
-
cpe:2.3:a:dronecode:px4_drone_autopilot:1.15.3
-
cpe:2.3:a:dronecode:px4_drone_autopilot:1.15.4