Time-of-Check to Time-of-Use Race Condition in Axis Device ACAP Framework
CVE-2026-5303
5.7MEDIUM
What is CVE-2026-5303?
The ACAP framework in Axis devices is affected by a Time-of-Check to Time-of-Use (TOCTOU) race condition, potentially allowing unauthorized privilege escalation. Exploitation requires the Axis device to permit the installation of unsigned ACAP applications, and for an attacker to persuade the victim to install a malicious application designed to exploit this flaw. This vulnerability highlights the importance of ensuring stringent application integrity on communication devices.
Affected Version(s)
AXIS OS 12.0.0 < 12.11.31
