Time-of-Check to Time-of-Use Race Condition in Axis Device ACAP Framework
CVE-2026-5303

5.7MEDIUM

Key Information:

Status
Vendor
CVE Published:
11 August 2026

What is CVE-2026-5303?

The ACAP framework in Axis devices is affected by a Time-of-Check to Time-of-Use (TOCTOU) race condition, potentially allowing unauthorized privilege escalation. Exploitation requires the Axis device to permit the installation of unsigned ACAP applications, and for an attacker to persuade the victim to install a malicious application designed to exploit this flaw. This vulnerability highlights the importance of ensuring stringent application integrity on communication devices.

Affected Version(s)

AXIS OS 12.0.0 < 12.11.31

References

CVSS V3.1

Score:
5.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Cookiejack15
.