An access control vulnerability in the mobile app (APK v5.5.0) for Ghost Robotics' Vision 60 robot allows multiple simultaneous sessions to run without proper client validation or session integrity checks. An attacker with a modified version of the app can connect to the robot during an active, legitimate session. This allows the attacker to bypass control restrictions, intercept sensitive information (such as real-time video), and partially interact with the system unnoticed and without disconnecting the legitimate user, compromising confidentiality and operational security.

Project Subscriptions

Vendors Products
Ghost Robotics Subscribe
Vision 60 Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution has been reported at this time.


Workaround

No workaround given by the vendor.

History

Mon, 27 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Ghost Robotics
Ghost Robotics vision 60
Vendors & Products Ghost Robotics
Ghost Robotics vision 60

Mon, 27 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Description An access control vulnerability in the mobile app (APK v5.5.0) for Ghost Robotics' Vision 60 robot allows multiple simultaneous sessions to run without proper client validation or session integrity checks. An attacker with a modified version of the app can connect to the robot during an active, legitimate session. This allows the attacker to bypass control restrictions, intercept sensitive information (such as real-time video), and partially interact with the system unnoticed and without disconnecting the legitimate user, compromising confidentiality and operational security.
Title Multiple vulnerabilities in Ghost Robotics' Vision 60
Weaknesses CWE-284
References
Metrics cvssV4_0

{'score': 7.7, 'vector': 'CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2026-07-27T15:45:49.434Z

Reserved: 2026-06-23T12:14:09.708Z

Link: CVE-2026-12990

cve-icon Vulnrichment

Updated: 2026-07-27T15:45:42.988Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-27T13:30:04Z

Weaknesses