Junglewise Threat Intelligence

CVE-2026-5304: Axis ACAP configuration input validation privilege escalation

CVE-2026-5304 · Severity: medium · CVSS 5.7 · Published 2026-08-11

Vendors: Axis.

Executive brief

Axis device firmware contains a flaw in its ACAP (Axis Camera Application Platform) configuration file validation that could allow an attacker to gain elevated privileges. The vulnerability requires an attacker to convince a user to install a malicious unsigned ACAP application on a device that has been configured to permit unsigned applications. If successful, an attacker could gain administrative access to the device.

Technical details

The vulnerability is an input validation flaw in the ACAP configuration file handling of Axis devices. The root cause stems from insufficient sanitization of configuration parameters during the ACAP application installation process. An attacker can craft a malicious ACAP application containing specially crafted configuration data that, when processed by the device, allows privilege escalation to administrative level. The attack requires two preconditions: (1) the target device must be configured to allow installation of unsigned ACAP applications, and (2) the victim must be socially engineered into installing the attacker's malicious application. Patches are available from Axis.

Affected products

  • Axis ACAP

Timeline

  • 2026-08-11: disclosed
  • 2026-08-11: advisory

References