PX4 Autopilot through 1.17.0 contains a null pointer dereference vulnerability in param_set_default_file() and param_set_backup_file() functions that allows attackers to crash the autopilot process. Attackers can invoke 'param select' or 'param select-backup' commands with no path argument from any PX4 shell to trigger the crash.
History

Tue, 08 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 04 Sep 2026 22:45:00 +0000

Type Values Removed Values Added
Description PX4 Autopilot through 1.17.0 contains a null pointer dereference vulnerability in param_set_default_file() and param_set_backup_file() functions that allows attackers to crash the autopilot process. Attackers can invoke 'param select' or 'param select-backup' commands with no path argument from any PX4 shell to trigger the crash.
Title PX4 Autopilot through 1.17.0 Null Pointer Dereference via param select
First Time appeared Px4
Px4 autopilot
Weaknesses CWE-476
CPEs cpe:2.3:a:px4:autopilot:*:*:*:*:*:*:*:*
Vendors & Products Px4
Px4 autopilot
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2026-09-04T22:38:47.363Z

Updated: 2026-09-08T13:02:26.613Z

Reserved: 2026-09-04T22:17:33.193Z

Link: CVE-2026-86097

cve-icon Vulnrichment

Updated: 2026-09-08T13:02:22.380Z

cve-icon NVD

Status : Received

Published: 2026-09-04T23:18:03.547

Modified: 2026-09-08T14:17:30.137

Link: CVE-2026-86097

cve-icon Redhat

No data.