CVE 9.3 CRITICAL

PX4 Autopilot Missing authentication for critical function_CVE-2026-1579

9.3 / 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Description

The MAVLink communication protocol does not require cryptographic
authentication by default. When MAVLink 2.0 message signing is not
enabled, any message -- including SERIAL_CONTROL, which provides
interactive shell access -- can be sent by an unauthenticated party with
access to the MAVLink interface. PX4 provides MAVLink 2.0 message
signing as the cryptographic authentication mechanism for all MAVLink
communication. When signing is enabled, unsigned messages are rejected
at the protocol level.

Basic Information

ID CVE-2026-1579
Source icscert
Published Mar 31, 2026 at 20:20
Modified Mar 31, 2026 at 20:36

Affected Product

Vendor PX4
Product Autopilot
Version v1.16.0 SITL
Affected Versions PX4 Autopilot v1.16.0 SITL

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.