An issue in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested affected version: commit abcdef1234567890 allows an attacker to cause unsafe trajectory… (CVE-2026-71644)
CVE-2026-71644 is a critical vulnerability in the Robotics-STAR-Lab RACER Tested software that allows an attacker to cause unsafe trajectory planning and potential UAV collisions. The flaw arises from a missing default case in the finite state machine (FSM) that stops publishing swarm trajectories when the drone enters the IDLE state. This can lead to unsafe behavior in drone swarm operations.
AI Analysis
Technical Summary
This vulnerability in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested, specifically in commit abcdef1234567890, is due to a missing default case in the FSM controlling swarm trajectory publication. When a drone enters the IDLE state, the FSM fails to stop publishing trajectories, potentially causing unsafe trajectory planning and UAV collisions. The CVSS 3.1 score is 9.8, indicating a critical severity with network attack vector, low complexity, no privileges or user interaction required, and high impact on confidentiality, integrity, and availability.
Potential Impact
An attacker can remotely trigger unsafe trajectory planning in drone swarms, potentially causing UAV collisions. This impacts the confidentiality, integrity, and availability of the system, posing significant safety risks in UAV operations.
Mitigation Recommendations
No patch or remediation information is provided. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, operators should carefully monitor drone states and consider manual intervention or disabling swarm operations when drones enter IDLE to prevent unsafe trajectory publication.
An issue in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested affected version: commit abcdef1234567890 allows an attacker to cause unsafe trajectory… (CVE-2026-71644)
Description
CVE-2026-71644 is a critical vulnerability in the Robotics-STAR-Lab RACER Tested software that allows an attacker to cause unsafe trajectory planning and potential UAV collisions. The flaw arises from a missing default case in the finite state machine (FSM) that stops publishing swarm trajectories when the drone enters the IDLE state. This can lead to unsafe behavior in drone swarm operations.
CVSS v3.1
Score 9.8critical
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested, specifically in commit abcdef1234567890, is due to a missing default case in the FSM controlling swarm trajectory publication. When a drone enters the IDLE state, the FSM fails to stop publishing trajectories, potentially causing unsafe trajectory planning and UAV collisions. The CVSS 3.1 score is 9.8, indicating a critical severity with network attack vector, low complexity, no privileges or user interaction required, and high impact on confidentiality, integrity, and availability.
Potential Impact
An attacker can remotely trigger unsafe trajectory planning in drone swarms, potentially causing UAV collisions. This impacts the confidentiality, integrity, and availability of the system, posing significant safety risks in UAV operations.
Mitigation Recommendations
No patch or remediation information is provided. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, operators should carefully monitor drone states and consider manual intervention or disabling swarm operations when drones enter IDLE to prevent unsafe trajectory publication.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-jh98-9grg-5fp6
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-71644"]
- Database Specific Severity
- CRITICAL
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6aa47ebe55bf5e2cf58579d7
Added to database: 09/11/2026, 22:20:46 UTC
Last enriched: 09/11/2026, 22:31:31 UTC
Last updated: 09/11/2026, 23:10:18 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.