Severe Bluetooth flaw allows hackers to take over DJI drones in mid-air
An attacker could knock it out of the sky.

Image by Cybernews
- A Bluetooth flaw affects 16 DJI drone models, including Mavic, Mini, Air, Neo, Flip, and Avata ranges.
- Nearby attackers could send commands without authentication to change settings, cut connections, or power off a drone.
- Researchers say a mid-air takeover is possible, but they have not demonstrated it in their proof of concept.
- The researchers also reported several other issues relating to DJI's drones last month.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
A gaping Bluetooth hole in 16 top-selling DJI drones could let a nearby hacker cut off the pilot and hijack the aircraft with no authentication required.
The bug affects the Chinese commercial drone maker’s Mavic and Mini ranges as well as Air 3, Air 3/3S, Neo, Flip, and Avata 2/360.
Security researchers Abdelrahman Yousef and Dr. Jordan Samhi discovered the flaw, tracked as CVE-2026-78306, in the way DJI drones authenticate commands sent through their Bluetooth interface.
The flaw has been rated 8.5 out of 10 for severity, meaning it is a critical vulnerability requiring immediate attention.
How it works
According to the flaw's description, Bluetooth is used to connect to the drone's WiFi interface and exchange network data, but researchers found that only 3 commands – retrieving the WiFi network's name, password and MAC address – actually check for a trusted Universally Unique Identifier (UUID).
Other commands lack that same check, meaning anyone within Bluetooth range could send unauthorized instructions using DUML – DJI's proprietary language for drone-to-controller communication.
The researchers' proof of concept (PoC) shows unauthenticated commands can:
- Change the WiFi password and SSID
- Alter wireless settings
- Disable or restart WiFi and Bluetooth
- Reboot or power off the aircraft
- Reset configurations
Some resets affect the aircraft’s system, flight controller, gimbal, camera, WiFi and software-defined radio configuration.
Other resets can format the aircraft's media storage and wipe its system logs.
Danger warning
In their disclaimer, the researchers warn that their PoC can cause “data loss, configuration changes, loss of connectivity, and device disruption,” and emphasize that it should only be used in controlled environments and on systems for which researchers are authorized to test.
The researchers add that their testing tool also deliberately places an additional confirmation step in front of commands they deem dangerous.
One command that resets the system, flight controller, gimbal, camera, WiFi, and software-defined radio configuration warns: “The FC configuration reset can restart the motors.”
Mid-air takeover?
An attacker could exploit these flaws to change the drone's WiFi password, break into its internal network, and potentially carve out a path to the flight control interface – gaining the ability to issue flight commands.
However, a mid-air takeover is a potential consequence rather than something that the researchers have demonstrated in their PoC.
There are currently no reports of this flaw being exploited in the wild, and it is not listed in CISA’s Known Exploited Vulnerability catalog.
Even if hackers don't fully take over a drone, the researchers admit that a "loss of connectivity" can occur – meaning the signal between the drone and the person flying it is cut off or disrupted.
With drones used for everything from photography and surveying to deliveries and police reconnaissance, disruption could have consequences well beyond the aircraft itself.
More DJI flaws discovered
CVE-2026-78306 was one of several DJI vulnerabilities Yousef and Samhi disclosed in August.
Other problems included a media server that didn't require a login to access, an FTP file-transfer service that used the same built-in password for every device, and a media server that leaked information it shouldn't have.
An earlier finding from August involved DUML data being sent over Bluetooth without encryption, meaning anyone nearby could potentially read it.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
Cybernews reached out to DJI for comment but received no immediate response.