Authentication Bypass Vulnerability in Device Configuration Framework by Axis
CVE-2026-6181
5.9MEDIUM
What is CVE-2026-6181?
The Device Configuration Framework by Axis contains a vulnerability that allows an attacker to bypass authentication restrictions. This flaw requires the attacker to initially authenticate using a viewer-privileged service account, which then enables the unauthorized access to potentially sensitive configurations. Proper safeguards must be adopted to mitigate risks associated with this vulnerability and prevent exploitation.
Affected Version(s)
AXIS OS 12.0.0 < 12.11.13
AXIS OS 11.11.0 < 11.11.207
