{"id":"CVE-2026-86097","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-86097","summary":"PX4 Autopilot through 1.17.0 contains a null pointer dereference vulnerability in param_set_default_file() and param_set_backup_file() functions that allows attackers to crash the autopilot…","details":"PX4 Autopilot through 1.17.0 contains a null pointer dereference vulnerability in param_set_default_file() and param_set_backup_file() functions that allows attackers to crash the autopilot process. Attackers can invoke 'param select' or 'param select-backup' commands with no path argument from any PX4 shell to trigger the crash.","published":"2026-09-04T23:18:03.547","modified":"2026-09-04T23:18:03.547","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":{"url":"https://github.com/PX4/PX4-Autopilot/commit/02eabc08c9b8cb1de525070cacb7ea0c495136f6","label":"PX4/PX4-Autopilot@02eabc0"},"references":[{"type":"WEB","url":"https://github.com/PX4/PX4-Autopilot"},{"type":"WEB","url":"https://github.com/PX4/PX4-Autopilot/blob/v1.17.0/src/lib/parameters/parameters.cpp"},{"type":"WEB","url":"https://github.com/PX4/PX4-Autopilot/commit/02eabc08c9b8cb1de525070cacb7ea0c495136f6"},{"type":"WEB","url":"https://github.com/PX4/PX4-Autopilot/pull/28475"},{"type":"WEB","url":"https://www.vulncheck.com/advisories/px4-autopilot-through-1.17.0-null-pointer-dereference-via-param-select"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-09-04T23:18:03.547"}}