Privilege Escalation Vulnerability in Axis Devices Due to ACAP Framework Flaw
CVE-2026-6505
5.1MEDIUM
What is CVE-2026-6505?
The ACAP framework in Axis devices has a vulnerability stemming from a Time-of-Check to Time-of-Use (TOCTOU) race condition. This issue can lead to privilege escalation when the Axis device is configured to accept unsigned ACAP applications. An attacker could exploit this by persuading the victim to install a malicious ACAP application, which could grant the attacker elevated privileges on the affected device. For more detailed information, refer to the official documentation.
Affected Version(s)
AXIS OS 12.0.0 < 12.11.44
