Back to overview

CVE-2026-12990

HIGH
7.7
CVSS 4.0
Description
An access control vulnerability in the mobile app (APK v5.5.0) for Ghost Robotics' Vision 60 robot allows multiple simultaneous sessions to run without proper client validation or session integrity checks. An attacker with a modified version of the app can connect to the robot during an active, legitimate session. This allows the attacker to bypass control restrictions, intercept sensitive information (such as real-time video), and partially interact with the system unnoticed and without disconnecting the legitimate user, compromising confidentiality and operational security.

Metadata

CVE ID
CVE-2026-12990
State
PUBLISHED
Assigner
INCIBE
Reserved
2026-06-23 12:14 UTC
Published
2026-07-27 11:38 UTC
Last updated
2026-07-27 15:45 UTC
Primary CWE
CWE-284
CWE-284 Improper Access Control
Vendor / Product
Ghost Robotics / Vision 60
Sources
cve.org  ·  NVD

Severity & Metrics

7.7 HIGH CVSS 4.0
CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
SSVC — CISA Coordinator
Exploitation
none
Automatable
no
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
Ghost Robotics Vision 60 5.5.0
Weakness (CWE)
CWESourceDescription
CWE-284 cna CWE-284 Improper Access Control
CVSS scores (1)
ScoreSeverityVersionSourceVector
7.7 HIGH 4.0 cna CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Back to overview