SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-12990

HIGH · CVSS 7.7 EPSS 0.13%

Source: NVD + CISA KEV + EPSS · Published 2026-07-27 · Last synced 2026-08-26

CyberRota Analysis

AI-Generated

The mobile app for Ghost Robotics' Vision 60 robot contains an access control vulnerability that permits multiple simultaneous sessions without adequate client validation or session integrity checks. This flaw enables an attacker using a modified app to connect to the robot during an active session, allowing them to bypass control restrictions, intercept sensitive data like real-time video, and interact with the system covertly. Organizations utilizing this robot should prioritize addressing this vulnerability to safeguard against potential breaches of confidentiality and operational security.

CVE
CVE-2026-12990
Severity
HIGH
CVSS
7.7
EPSS
0.13%

Original NVD Description

An access control vulnerability in the mobile app (APK v5.5.0) for Ghost Robotics' Vision 60 robot allows multiple simultaneous sessions to run without proper client validation or session integrity checks. An attacker with a modified version of the app can connect to the robot during an active, legitimate session. This allows the attacker to bypass control restrictions, intercept sensitive information (such as real-time video), and partially interact with the system unnoticed and without disconnecting the legitimate user, compromising confidentiality and operational security.