Description
The Device Configuration Framework is vulnerable to an authentication bypass flaw. This flaw can only be exploited after authenticating with a viewer-privileged service account.
Published: 2026-08-11
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Device Configuration Framework of Axis Communications AB AXIS OS has a flaw that allows an authenticated user with viewer privileges to bypass normal authorization checks. An attacker with such an account could access configuration functions that normally require higher authority, potentially enabling unauthorized configuration changes, data exposure or device compromise.

Affected Systems

Axis Communications AB AXIS OS devices are affected. The advisory does not list specific firmware or software version numbers, so all installations of the mentioned framework should be considered vulnerable.

Risk and Exploitability

The CVSS score of 5.9 indicates moderate severity. No EPSS value is available and the vulnerability is not listed in CISA KEV, suggesting no known widespread exploitation. The exploit requires a viewer‑privileged service account, which implies an internal attack or credential compromise. Based on the description, it is inferred that the attack vector requires authenticated access, likely from within the network or from a compromised account.

Generated by OpenCVE AI on August 11, 2026 at 07:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Disable or restrict the use of viewer‑privileged service accounts to the minimum required function set.
  • Apply the vendor‑issued fix for the Device Configuration Framework as soon as it becomes available.
  • Monitor configuration changes and audit logs for signs of unauthorized activity.

Generated by OpenCVE AI on August 11, 2026 at 07:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 11 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
Title Authentication Bypass in Axis Device Configuration Framework
First Time appeared Axis Communications Ab
Axis Communications Ab axis Os
Vendors & Products Axis Communications Ab
Axis Communications Ab axis Os

Tue, 11 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Description The Device Configuration Framework is vulnerable to an authentication bypass flaw. This flaw can only be exploited after authenticating with a viewer-privileged service account.
Weaknesses CWE-290
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Axis Communications Ab Axis Os
cve-icon MITRE

Status: PUBLISHED

Assigner: Axis

Published:

Updated: 2026-08-11T14:19:20.634Z

Reserved: 2026-04-13T05:53:13.103Z

Link: CVE-2026-6181

cve-icon Vulnrichment

Updated: 2026-08-11T14:19:17.100Z

cve-icon NVD

Status : Received

Published: 2026-08-11T06:17:16.850

Modified: 2026-08-11T15:17:35.143

Link: CVE-2026-6181

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-11T07:30:03Z

Weaknesses
  • CWE-290

    Authentication Bypass by Spoofing