PT-2026-79837 · Dji · Mavic 3+15

·

CVE-2026-78255

·

Published

2026-08-24

·

Updated

2026-08-25

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions DJI Neo versions prior to 01.00.0400 DJI Neo 2 versions prior to 01.00.0500 DJI Flip versions prior to 01.00.1200 DJI Air 3 versions prior to 01.00.1600 DJI Air 3S versions prior to 01.00.1400 DJI Avata 2 versions prior to 01.00.0400 DJI Avata 360 versions prior to 01.00.0300 DJI Mavic 3 versions prior to 01.00.1400 DJI Mavic 3 Classic versions prior to 01.00.0800 DJI Mavic 3 Pro versions prior to 01.01.0700 DJI Mavic 4 Pro versions prior to 01.00.0500 DJI Mini 2 versions prior to 01.07.0200 DJI Mini 3 versions prior to 01.00.0500 DJI Mini 3 Pro versions prior to 01.00.0900 DJI Mini 4 Pro versions prior to 01.00.1100 DJI Mini 5 Pro versions prior to 01.00.0600
Description The HTTP media server on certain drones serves stored photos and videos through the /v2 endpoint without requiring client authentication. Because filenames follow a predictable pattern, an attacker on the drone's internal network can enumerate filenames to exfiltrate media. This exposure may reveal sensitive data such as private locations, travel history, and identifiable individuals.
Recommendations Update DJI Neo to version 01.00.0400 or later. Update DJI Neo 2 to version 01.00.0500 or later. Update DJI Flip to version 01.00.1200 or later. Update DJI Air 3 to version 01.00.1600 or later. Update DJI Air 3S to version 01.00.1400 or later. Update DJI Avata 2 to version 01.00.0400 or later. Update DJI Avata 360 to version 01.00.0300 or later. Update DJI Mavic 3 to version 01.00.1400 or later. Update DJI Mavic 3 Classic to version 01.00.0800 or later. Update DJI Mavic 3 Pro to version 01.01.0700 or later. Update DJI Mavic 4 Pro to version 01.00.0500 or later. Update DJI Mini 2 to version 01.07.0200 or later. Update DJI Mini 3 to version 01.00.0500 or later. Update DJI Mini 3 Pro to version 01.00.0900 or later. Update DJI Mini 4 Pro to version 01.00.1100 or later. Update DJI Mini 5 Pro to version 01.00.0600 or later.

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-78255

Affected Products

Air 3
Air 3S
Avata 2
Avata 360
Flip
Mavic 3
Mavic 3 Classic
Mavic 3 Pro
Mavic 4 Pro
Mini 2
Mini 3
Mini 3 Pro
Mini 4 Pro
Mini 5 Pro
Neo
Neo 2