Junglewise Threat Intelligence

CVE-2026-8158: Axis Signed Video Framework buffer overflow

CVE-2026-8158 · Severity: medium · CVSS 5.3 · Published 2026-08-11

Vendors: Axis.

Executive brief

Axis Signed Video Framework contains a buffer overflow vulnerability that could cause applications using the framework to crash or malfunction. The issue affects only the validation tools for signed content, not the core signed video functionality in AXIS OS devices themselves. Exploitation could lead to application unavailability or unexpected behavior.

Technical details

A buffer overflow vulnerability exists in the Signed Video Framework, specifically in the validation tools used to process signed content. The vulnerability is triggered during the parsing or validation of signed video data, allowing an attacker to overwrite memory and crash the affected application. This vulnerability exclusively impacts the validation/verification tools rather than the core signed video functionality within AXIS OS devices. The attack vector requires providing malformed signed content to the validation tools. No patch information is provided in the advisory.

Affected products

  • Axis Signed Video Framework

Timeline

  • 2026-08-11: disclosed

References