Description
PX4 Autopilot versions 1.12.x through 1.15.x contain a protection mechanism failure in the "Re-arm Grace Period" logic. The system incorrectly applies the in-air emergency re-arm logic to ground scenarios. If a pilot switches to Manual mode and re-arms within 5 seconds (default configuration) of an automatic landing, the system bypasses all pre-flight safety checks, including the throttle threshold check. This allows for an immediate high-thrust takeoff if the throttle stick is raised, leading to loss of control.
Published: 2026-03-10
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Loss of Control
Action: Patch Immediately
AI Analysis

Impact

PX4 Autopilot versions 1.12.x through 1.15.x contain a flaw in the Re‑arm Grace Period logic where the system mistakenly applies in‑air emergency re‑arm rules during ground scenarios. This incorrect permission enforcement flaw (CWE‑862) causes the protection mechanism to bypass all pre‑flight safety checks, including the critical throttle threshold check, when a pilot switches to Manual mode and re‑arms within the default 5‑second grace period of an automatic landing. The result is an immediate high‑thrust takeoff when the throttle stick is raised, leading to loss of control and potential safety incidents.

Affected Systems

The vulnerability affects PX4 Autopilot firmware from version 1.12.x up to 1.15.x. Affected users should verify their installed PX4 version and identify whether it resides within this range.

Risk and Exploitability

The flaw carries a CVSS score of 8.1, indicating high severity, but the EPSS score is below 1 %, suggesting a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. An attacker would need the ability to command a mode switch to Manual during a landing sequence, either through the remote controller or by compromising the aviation system, to trigger the bypass. Once the grace period is exploited, safety checks are circumvented and high‑thrust takeoff becomes possible, presenting a direct risk of loss of control.

Generated by OpenCVE AI on April 16, 2026 at 10:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor’s security patch for PX4 Autopilot versions 1.12.x–1.15.x that corrects the Re‑arm Grace Period logic.
  • If a patch is unavailable, disable the Re‑arm Grace Period feature or set its duration to zero so that safety checks are performed before re‑arm.
  • Enforce pre‑flight safety checks manually after re‑arm, such as unlocking the throttle threshold check regardless of mode, to recover the safety net.
  • Update the PX4 firmware to the latest released version as soon as an official fix is issued.

Generated by OpenCVE AI on April 16, 2026 at 10:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 16 Apr 2026 10:15:00 +0000

Type Values Removed Values Added
Title PX4 Autopilot Re‑arm Grace Period Logic Bypass Enabling Immediate Takeoff and Loss of Control

Thu, 12 Mar 2026 17:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:dronecode:px4_drone_autopilot:*:*:*:*:*:*:*:*

Wed, 11 Mar 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H'}


Wed, 11 Mar 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Dronecode
Dronecode px4 Drone Autopilot
Vendors & Products Dronecode
Dronecode px4 Drone Autopilot

Tue, 10 Mar 2026 19:00:00 +0000

Type Values Removed Values Added
Description PX4 Autopilot versions 1.12.x through 1.15.x contain a protection mechanism failure in the "Re-arm Grace Period" logic. The system incorrectly applies the in-air emergency re-arm logic to ground scenarios. If a pilot switches to Manual mode and re-arms within 5 seconds (default configuration) of an automatic landing, the system bypasses all pre-flight safety checks, including the throttle threshold check. This allows for an immediate high-thrust takeoff if the throttle stick is raised, leading to loss of control.
References

Subscriptions

Dronecode Px4 Drone Autopilot
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-03-11T14:51:09.728Z

Reserved: 2026-02-16T00:00:00.000Z

Link: CVE-2026-26742

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-03-10T19:17:17.280

Modified: 2026-03-12T17:05:45.557

Link: CVE-2026-26742

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-16T10:00:14Z

Weaknesses