CVE-2026-12991
CVE-2026-12991 is a high-severity vulnerability with a CVSS 4.0 base score of 8.7. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-300.
Key facts
- Severity: High (CVSS 4.0 base score 8.7)
- EPSS exploit prediction: 0% (4th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-300
- Published:
- Last modified:
Description
The lack of cryptographic mechanisms to ensure the integrity and authenticity of communications in Ghost Robotics' Vision 60 robot (APK v5.5.0) exposes the system to man-in-the-middle attacks. An attacker located on the local network can use ARP spoofing and selective traffic blocking techniques to intercept and manipulate packets between the legitimate operator and the robot. This allows the attacker to disconnect the original controller, establish unauthorized communications, and prevent the operator from regaining control of the device, seriously compromising the confidentiality, integrity, and availability (CIA) of operations.
Frequently asked questions
- What is CVE-2026-12991?
- The lack of cryptographic mechanisms to ensure the integrity and authenticity of communications in Ghost Robotics' Vision 60 robot (APK v5.5.0) exposes the system to man-in-the-middle attacks. An attacker located on the local network can use ARP spoofing and selective traffic blocking techniques to intercept and manipulate packets between the legitimate operator and the robot. This allows the attacker to disconnect the original controller, establish unauthorized communications, and prevent the operator from regaining control of the device, seriously compromising the confidentiality, integrity, and availability (CIA) of operations.
- How severe is CVE-2026-12991?
- CVE-2026-12991 has a CVSS 4.0 base score of 8.7, rated high severity.
- Is CVE-2026-12991 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (4th percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2026-12991?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2026-12991 published?
- CVE-2026-12991 was published on 2026-07-27.
References
Other CWE-300 vulnerabilities
- CVE-2023-31004 — High (CVSS 8.3): IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security…
- CVE-2024-31206 — High (CVSS 8.2): dectalk-tts is a Node package to interact with the aeiou Dectalk web API. In `[email protected]`, network requests to…
- CVE-2025-31214 — High (CVSS 8.1): This issue was addressed through improved state management. This issue is fixed in iOS 18.5 and iPadOS 18.5. An…
- CVE-2024-36553 — High (CVSS 8.1): Forever KidsWatch Call Me KW-50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h is vulnerable to MITM attack.
- CVE-2021-21953 — High (CVSS 8.1): An authentication bypass vulnerability exists in the process_msg() function of the home_security binary of Anker Eufy…
- CVE-2021-41033 — High (CVSS 8.1): In all released versions of Eclipse Equinox, at least until version 4.21 (September 2021), installation can be…