Description
An access control vulnerability in the mobile app (APK v5.5.0) for Ghost Robotics' Vision 60 robot allows multiple simultaneous sessions to run without proper client validation or session integrity checks. An attacker with a modified version of the app can connect to the robot during an active, legitimate session. This allows the attacker to bypass control restrictions, intercept sensitive information (such as real-time video), and partially interact with the system unnoticed and without disconnecting the legitimate user, compromising confidentiality and operational security.
Published: 2026-07-27
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Ghost Robotics’ Vision 60 mobile application APK version 5.5.0 contains an access control flaw that permits a malicious user to establish new, simultaneous sessions while a legitimate session is in progress, bypassing required client validation and session integrity checks. By exploiting this weakness, an attacker with a modified version of the app may intercept live data streams such as video, partially issue commands, and remain unseen as the original user continues to interact with the robot, thereby compromising the confidentiality of transmitted information and operational security.

Affected Systems

The only component currently known to be vulnerable is the Vision 60 robot’s mobile control app (APK 5.5.0). No other product lines or versions are listed as affected.

Risk and Exploitability

The CVSS score of 7.7 reflects high severity; the EPSS score of less than 1% indicates a very low but non‑zero probability of exploitation, and the vulnerability is not present in the CISA KEV catalog. An attacker would need to supply a tampered version of the client and have network access to the robot—most likely over the local or remote control interface. The attack vector is inferred to be network‑based, requiring manipulation of the client application to bypass session validation.

Generated by OpenCVE AI on August 3, 2026 at 17:47 UTC.

Remediation

Vendor Solution

No solution has been reported at this time.


OpenCVE Recommended Actions

  • Restrict the robot’s network interface so that only trusted devices can initiate control sessions, for example by applying firewall rules or network segmentation.
  • Disable remote control features that are unnecessary for operations, or enforce mandatory authentication before any session can be created.
  • Configure the robot’s logging to capture session initiation attempts, and monitor these logs for simultaneous sessions or unauthorized connections; trigger alerts for any suspicious activity.
  • If possible, route all control traffic through a VPN or isolated network segment to limit exposure to untrusted networks.

Generated by OpenCVE AI on August 3, 2026 at 17:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Ghost Robotics
Ghost Robotics vision 60
Vendors & Products Ghost Robotics
Ghost Robotics vision 60

Mon, 27 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Description An access control vulnerability in the mobile app (APK v5.5.0) for Ghost Robotics' Vision 60 robot allows multiple simultaneous sessions to run without proper client validation or session integrity checks. An attacker with a modified version of the app can connect to the robot during an active, legitimate session. This allows the attacker to bypass control restrictions, intercept sensitive information (such as real-time video), and partially interact with the system unnoticed and without disconnecting the legitimate user, compromising confidentiality and operational security.
Title Multiple vulnerabilities in Ghost Robotics' Vision 60
Weaknesses CWE-284
References
Metrics cvssV4_0

{'score': 7.7, 'vector': 'CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Ghost Robotics Vision 60
cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2026-07-27T15:45:49.434Z

Reserved: 2026-06-23T12:14:09.708Z

Link: CVE-2026-12990

cve-icon Vulnrichment

Updated: 2026-07-27T15:45:42.988Z

cve-icon NVD

Status : Deferred

Published: 2026-07-27T13:16:52.130

Modified: 2026-07-27T20:32:11.620

Link: CVE-2026-12990

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T18:00:11Z

Weaknesses