Executive brief
A security vulnerability exists in Axis network devices that could allow an attacker to gain higher-level administrative control over the system. To exploit this, an attacker must first convince a user to install a specially crafted, malicious application on a device that has been configured to allow unsigned software. This could lead to a full compromise of the device, affecting its availability and the security of the data it processes.
Technical details
A path traversal vulnerability (CWE-35) exists in the ACAP (AXIS Camera Application Platform) configuration file due to insufficient input validation. An attacker can exploit this by creating a malicious ACAP application that uses path traversal sequences to access or modify restricted files. Successful exploitation requires the target Axis device to be configured to allow the installation of unsigned ACAP applications and requires the attacker to trick an authorized user into installing the malicious package. This can result in local privilege escalation, granting the attacker elevated permissions on the AXIS OS.
Affected products
- Axis Communications AXIS OS 12.0.0 to 12.10.4
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory