Description
The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race condition, which could potentially lead to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to install a malicious ACAP application.
Published: 2026-08-11
Score: 5.1 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The ACAP framework in Axis OS contains a Time‑of‑Check to Time‑of‑Use (TOCTOU) race condition that may allow an attacker to elevate privileges. This weakness can be exploited only if the device is configured to permit installation of unsigned ACAP applications and an attacker succeeds in convincing the user to install a malicious ACAP module. If executed, the attacker could gain elevated rights on the device, potentially compromising its confidentiality, integrity or availability.

Affected Systems

Axis Communications AB Axis OS devices that allow unsigned ACAP installations are impacted. No specific version information is given, so any device with the default or custom configuration permitting unsigned ACAPs should be assessed.

Risk and Exploitability

The vulnerability is scored ‑ CVSS 5.1, which indicates moderate risk. EPSS is unavailable, and the issue is not listed in the CISA KEV catalog. The likely attack vector is social engineering or other means to persuade a user to install a malicious unsigned ACAP, after which the TOCTOU race condition could be triggered to gain higher privileges. No further exploitation prerequisites are described, so the threat remains confined to devices configured to accept unsigned ACAP applications.

Generated by OpenCVE AI on August 11, 2026 at 07:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Disable installation of unsigned ACAP applications via device settings.
  • Apply any available vendor patches or firmware updates that fix the ACAP TOCTOU issue.
  • Verify and remove any installed ACAPs that are not vendor‑signed or that originate from untrusted sources.

Generated by OpenCVE AI on August 11, 2026 at 07:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 11 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
First Time appeared Axis Communications Ab
Axis Communications Ab axis Os
Vendors & Products Axis Communications Ab
Axis Communications Ab axis Os

Tue, 11 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Description The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race condition, which could potentially lead to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to install a malicious ACAP application.
Weaknesses CWE-367
References
Metrics cvssV3_1

{'score': 5.1, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:L/A:L'}


Subscriptions

Axis Communications Ab Axis Os
cve-icon MITRE

Status: PUBLISHED

Assigner: Axis

Published:

Updated: 2026-08-11T05:49:51.278Z

Reserved: 2026-04-17T10:41:05.220Z

Link: CVE-2026-6505

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-11T07:30:03Z

Weaknesses
  • CWE-367

    Time-of-check Time-of-use (TOCTOU) Race Condition