Input Validation Flaw in Axis Device Configurations
CVE-2026-1185

5.4MEDIUM

Key Information:

Status
Vendor
CVE Published:
12 May 2026

What is CVE-2026-1185?

A configuration file on the local filesystem of Axis devices has improper input validation, which may enable an attacker to execute arbitrary code and escalate privileges. For exploitation to occur, the attacker must have previously authenticated to the Axis device via SSH. This vulnerability poses a significant security risk if not addressed, as it could allow unauthorized users to gain elevated access and control over the affected device.

Affected Version(s)

AXIS OS 12.0.0 < 12.10.36

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Cookiejack15
.