Junglewise Threat Intelligence

CVE-2026-5303: Axis ACAP framework privilege escalation via TOCTOU race condition

CVE-2026-5303 · Severity: medium · CVSS 5.7 · Published 2026-08-11

Vendors: Axis.

Executive brief

Axis ACAP is a framework for running applications on Axis network devices such as cameras and access controllers. A timing vulnerability in this framework could allow an attacker to escalate privileges by exploiting the gap between permission checks and application execution. This risk is limited to devices configured to accept unsigned applications, and requires social engineering to trick users into installing a malicious app.

Technical details

The vulnerability is a classic Time-of-Check to Time-of-Use (TOCTOU) race condition in the ACAP framework's permission validation logic. An attacker can modify application files or permissions between the security check and the actual application execution, potentially gaining elevated privileges on the device. Exploitation requires: (1) the target device configured to allow unsigned ACAP applications, and (2) the user to be socially engineered into installing a malicious ACAP application. The attack window is narrow and race-condition dependent, making reliable exploitation difficult. A patch from Axis should be available to address the race condition.

Affected products

  • Axis ACAP framework

Timeline

  • 2026-08-11: disclosed

References

Related threats