Junglewise Threat Intelligence

CVE-2026-6505: Axis ACAP framework TOCTOU race condition

CVE-2026-6505 · Severity: medium · CVSS 5.1 · Published 2026-08-11

Vendors: Axis.

Executive brief

Axis devices running the ACAP framework contain a race condition in application installation logic. An attacker could exploit this to escalate privileges on affected devices, but only if the device allows unsigned application installation and the victim installs a malicious application. This could lead to unauthorized control of the device and access to its capabilities.

Technical details

The vulnerability is a Time-of-Check to Time-of-Use (TOCTOU) race condition in the ACAP framework's privilege handling during application installation. The flaw exists in the window between security validation and execution of an ACAP application, allowing an attacker to modify application behavior to gain elevated privileges. Exploitation requires two conditions: the target Axis device must be configured to permit unsigned ACAP application installation, and an attacker must convince a user to install a malicious application. An attacker with code execution through an ACAP application can leverage the TOCTOU condition to escalate privileges beyond the application's intended sandbox. Patches are expected from Axis for affected device models.

Affected products

  • Axis ACAP framework

Timeline

  • 2026-08-11: disclosed

References

Related threats