External risk intelligence

Robotics-STAR-Lab RACER Unsafe Trajectory Planning Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-71644

The vulnerability affects trajectory planning and flight state management software for UAVs (drones). Such software operates in specialized, local, or physical environments controlling hardware movement and is not a service or application designed for public internet exposure or remote accessibility.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability exists in specific drone trajectory planning software, where a missing default case can lead to unsafe flight path calculations and potential collisions. This issue could impact operational safety and system reliability. The primary concern is confirming if this specific software is in use within our environment.

  • Software flaw causes unsafe drone flight plans.
  • Potential for drone collisions if not addressed.
  • Confirm relevance and exposure within our drone systems.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending specially crafted data to the drone's trajectory planning system. This could lead to the system entering an unsafe state, potentially causing collisions between drones.

  • No authentication or user interaction needed.
  • Triggered by entering an IDLE state.
  • Risk of unsafe trajectory planning and collisions.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could affect the safe operation of Unmanned Aerial Vehicles (UAVs) by causing them to plan unsafe flight paths, potentially leading to collisions. This may occur when the drone enters an idle state due to a missing default case in the flight state machine that stops the publishing of swarm trajectories.

  • UAV trajectory planning and swarm coordination.
  • Malicious input may disrupt trajectory publishing.
  • Unsafe flight paths and drone collisions.

Operational Fix

Recommended remediation, mitigation, and detection steps

Given the vulnerability's impact on UAV trajectory planning and the potential for collisions, the primary responsibility likely falls to the teams managing the drone fleet and their control systems. This includes the flight operations team, the system owners responsible for the Robotics-STAR-Lab software, and potentially the cybersecurity team for risk assessment and coordination. The immediate first step is to identify all instances of the affected software, confirm its operational status and criticality, and determine the specific ownership of each deployment before planning any remediation.

  • Own by drone fleet and control system managers.
  • Verify drone fleet and control system inventory.
  • Plan operational downtime for affected systems.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Robotics-STAR-Lab RACER?

RACER is a specialized software framework developed by the SYSU STAR Group for unmanned aerial vehicles (UAVs). It handles complex tasks like trajectory planning and swarm coordination, which allow multiple drones to navigate and operate safely together in a unified flight group.

What does CVE-2026-71644 mean by a missing default case?

This refers to a software weakness class known as Type Confusion (CWE-843). In this context, the flight state machine lacks instructions for how to handle specific conditions. Because it fails to account for every scenario, the system behaves unexpectedly when it should be managing safety protocols.

How is this vulnerability triggered?

The flaw is triggered when the drone enters an IDLE state. If the software lacks a proper default case to handle this transition, it stops publishing swarm trajectory data. Normal operational activities that do not involve transitioning into this specific IDLE state do not trigger this faulty logic.

Is this vulnerability reachable from the internet?

Halo Surface Signal indicates it is very unlikely for this issue to be reached via the public internet. The affected software governs physical drone movement and trajectory planning, which typically operate within localized, restricted, or private physical environments rather than as public-facing services.

How should I respond if I use this software?

First, inventory your drone fleet and control systems to confirm if the affected version of RACER is installed. Once identified, work with your flight operations and system engineering teams to assess the risk to your specific deployment and coordinate a path toward updating the software to a secured state.

References