Description
The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race condition, which could potentially lead to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to install a malicious ACAP application.
Published: 2026-08-11
Score: 5.7 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The ACAP framework contains a Time-of-Check to Time-of-Use race condition, which could allow a user to gain higher privileges on an Axis OS device. If the device permits installation of unsigned ACAP applications and a malicious ACAP is installed, the attacker could execute privileged actions or compromise the device. The weakness is a concurrency bug that violates atomicity during permission checks.

Affected Systems

Axis Communications AB's AXIS OS is impacted. No specific version information is disclosed by the vendor, but the vulnerability exists in the ACAP framework used across multiple devices running AXIS OS. Any device configured to allow unsigned ACAP applications is vulnerable.

Risk and Exploitability

The CVSS score of 5.7 indicates medium severity, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a configuration that allows unsigned ACAP applications and a user to be persuaded to install a malicious ACAP. The likely attack vector is social engineering combined with misconfiguration, and it can be exploited locally once the device is configured to permit unsigned apps.

Generated by OpenCVE AI on August 11, 2026 at 07:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Disable installation of unsigned ACAP applications on all Axis devices.
  • Apply the latest security patch from Axis Communications that addresses the TOCTOU race condition in the ACAP framework.
  • If a patch is not yet released, consider removing all existing unsigned ACAP applications and block new installations until an update is available.
  • Monitor device logs for installation attempts of unsigned ACAP applications and investigate any suspicious activity.

Generated by OpenCVE AI on August 11, 2026 at 07:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 11 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
Title Time-of-Check to Time-of-Use Race Condition in ACAP Framework Enables Privilege Escalation on Axis OS
First Time appeared Axis Communications Ab
Axis Communications Ab axis Os
Vendors & Products Axis Communications Ab
Axis Communications Ab axis Os

Tue, 11 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Description The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race condition, which could potentially lead to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to install a malicious ACAP application.
Weaknesses CWE-367
References
Metrics cvssV3_1

{'score': 5.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N'}


Subscriptions

Axis Communications Ab Axis Os
cve-icon MITRE

Status: PUBLISHED

Assigner: Axis

Published:

Updated: 2026-08-11T05:45:56.671Z

Reserved: 2026-04-01T08:19:11.184Z

Link: CVE-2026-5303

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-11T07:30:03Z

Weaknesses
  • CWE-367

    Time-of-check Time-of-use (TOCTOU) Race Condition