Junglewise Threat Intelligence

CVE-2026-0541: Axis AXIS OS privilege escalation in ACAP installation

CVE-2026-0541 · Severity: medium · CVSS 6.7 · Published 2026-05-12

Technologies: Axis Communications OS, Axis Os. Vendors: Axis Communications, Axis.

Executive brief

Axis Communications devices running AXIS OS are affected by a security flaw that allows malicious applications to gain unauthorized administrative control. This occurs when a user is tricked into installing a specially crafted application on a device that has been configured to allow unsigned software. If exploited, an attacker could gain full control over the device, potentially compromising video feeds, security settings, and network integrity.

Technical details

A privilege escalation vulnerability exists in AXIS OS due to improper input validation (CWE-732) during the installation process of AXIS Camera Application Platform (ACAP) applications. An attacker can exploit this by creating a malicious ACAP application that, when installed, gains elevated system privileges. The attack requires the target device to be configured to allow the installation of unsigned ACAP applications and typically involves social engineering to convince an administrator to perform the installation. Successful exploitation allows the application to bypass intended permission boundaries, leading to a full compromise of the device's confidentiality, integrity, and availability. The issue is addressed in AXIS OS version 12.9.32.

Affected products

  • Axis Communications AXIS OS 12.0.0 to 12.9.32

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory

References

Related threats