A Reported Bluetooth Flaw Just Put 16 DJI Drones Under the Microscope
Sep 24, 2026
Share:

Something may be wrong with the Bluetooth security of several DJI drones, but it is too early to say that hackers can simply take control of them in midair. A vulnerability documented by the National Vulnerability Database in August and reported by CyberNews in September describes a way for someone within Bluetooth range to send unauthorized commands to affected drones.
The researchers demonstrated several ways to disrupt the aircraft, while a full midair takeover remains a potential consequence they have not demonstrated.
That distinction matters. The finding is serious enough to deserve attention, but it also needs more independent scrutiny from security researchers who can verify how far an attacker could actually go.
What Is the National Vulnerability Database?
The National Vulnerability Database, or NVD, is a public repository maintained by the US National Institute of Standards and Technology. It collects information about publicly disclosed cybersecurity vulnerabilities, including affected products, technical descriptions and references to research.
An NVD listing does not necessarily mean NIST itself discovered or independently reproduced a vulnerability. The DJI entries identify CIRCL as their source.
The Bluetooth command issue is tracked as CVE 2026 78306. It affects 16 DJI models, including the Neo, Flip, Air 3, Air 3S, Avata 2, Avata 360, Mavic 3 series, Mavic 4 Pro and several Mini models.

What Can an Attacker Actually Do?
The vulnerability involves DJI’s DUML, or DJI Universal Markup Language protocol, which is used for communication between components of the drone.
According to the vulnerability description, some commands sent through Bluetooth do not properly authenticate the sender. Someone within Bluetooth range could potentially use those commands to modify WiFi settings, including the network name, and password.
That could allow an attacker to connect to the drone’s internal WiFi network. Other commands could disable or restart WiFi and Bluetooth, disconnect clients or reset wireless settings.
Those actions could interrupt the pilot’s wireless connection to the aircraft, potentially affecting flight control, video and telemetry.
CyberNews reports that researchers demonstrated these unauthorized commands and several disruptive actions. However, the researchers did not demonstrate an actual midair takeover in their proof of concept. CyberNews describes that scenario as a possible consequence if an attacker could reach the relevant flight control interface. There are also no known reports of the vulnerability being exploited in the wild.

Why This Deserves a Closer Look
For drone photographers, losing a wireless connection is already a concern. A connection disruption during flight could mean losing live video or telemetry at a critical moment, even without an attacker gaining control of the aircraft.
That makes the distinction between a demonstrated exploit and a theoretical attack particularly important. The current evidence shows that unauthorized commands can be sent and that connectivity can be disrupted. It does not establish that someone can reliably fly an affected DJI drone remotely.
That is also where independent testing could be useful. Other security researchers may be able to reproduce the findings, determine the practical range required for an attack, and establish exactly what access can be obtained after the attacker reaches the internal network.
DJI Already Faces Security Scrutiny
The vulnerability also arrives at a complicated time for DJI in the US.
The company has faced years of scrutiny from US lawmakers and agencies over national security and data security concerns. In December 2025, the Federal Communications Commission added foreign produced unmanned aircraft systems and related equipment to its Covered List following a national security determination.
Those government concerns are separate from this particular Bluetooth vulnerability. The existence of a security flaw does not, by itself, prove the broader allegations made about DJI’s products or practices.
Still, the timing helps explain why a technical finding involving DJI can attract considerable attention.

For Now, Check Your Firmware
The NVD entries identify specific firmware versions as affected, and the listed remediation is a firmware update. Owners of affected drones should therefore check DJI’s current firmware and update the aircraft if an applicable fix is available.
For now, the most accurate takeaway is not that DJI drones are suddenly vulnerable to remote hijacking. It is that researchers have identified a potentially important wireless security weakness, demonstrated some of its consequences, and left a more serious question open.
And sometimes an unanswered security question is exactly what other researchers need to see before they start testing it themselves.
Alysa Gavilan
Alysa Gavilan has spent years exploring photography through photojournalism and street scenes. She enjoys working with both film and mirrorless cameras, and her fascination with the craft has grown over the decades. Inspired by Vivian Maier, she is drawn to capturing everyday moments that often go unnoticed.

































Join the Discussion
DIYP Comment Policy
Be nice, be on-topic, no personal information or flames.