CVE-2026-12990
Ghost Robotics · Vision 60
An access control vulnerability in the Ghost Robotics Vision 60 mobile application (version 5.5.0) could allow unauthorized parties to interact with the device.
Executive summary
A high-severity access control flaw in the Ghost Robotics Vision 60 mobile application may allow unauthorized individuals to gain control over the affected robotics system.
Vulnerability
The vulnerability is an improper access control issue (CWE-284). It allows an attacker with adjacent network access to bypass intended security restrictions, as indicated by the CVSS 4.0 vector.
Business impact
The Vision 60 is a specialized robotics platform, and unauthorized access could lead to the loss of operational control, physical safety risks, or the compromise of sensitive deployment environments. The CVSS score of 7.7 highlights the significant danger posed by unauthorized access to industrial or autonomous hardware.
Remediation
Immediate Action: Since no official patch is currently available, restrict network access to the robotic systems and the associated control applications to authorized, isolated networks only.
Proactive Monitoring: Monitor network traffic for any unauthorized attempts to connect to the Vision 60 control interface or the mobile application.
Compensating Controls: Implement robust network segmentation and firewalls to prevent unauthorized devices from reaching the control interface of the Vision 60 system.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Users of the Ghost Robotics Vision 60 should immediately isolate these devices from public or untrusted networks. Until a vendor-provided update is released, strict physical and network-level security controls remain the only effective method to mitigate this risk.