Junglewise Threat Intelligence

CVE-2026-1185: Axis AXIS OS privilege escalation via configuration file

CVE-2026-1185 · Severity: medium · CVSS 5.4 · Published 2026-05-12

Technologies: Axis Communications OS, Axis Os. Vendors: Axis Communications, Axis.

Executive brief

A vulnerability in Axis network devices, such as security cameras and encoders, could allow an authorized user to gain higher-level system permissions. By modifying a specific configuration file, an attacker who already has SSH access to the device can execute unauthorized code. This could lead to a full takeover of the device, potentially compromising the security of the video surveillance network.

Technical details

An improper input validation vulnerability exists in a local configuration file within AXIS OS. The flaw, classified under CWE-732 (Incorrect Permission Assignment for Critical Resource), allows an attacker with existing SSH access and low-level privileges to modify system configurations to execute arbitrary code. This can result in local privilege escalation to a higher-privileged user or root. The attack vector is listed as network-based because SSH is the primary entry point, though it requires valid credentials (PR:L). Axis has addressed this in AXIS OS versions 12.10.37 and later.

Affected products

  • Axis Communications AXIS OS 12.0.0 to 12.10.37

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory
  • 2026-05-19: other: NVD analysis updated

References

Related threats