CVE-2026-0804 Details
Description
An ACAP configuration file lacked sufficient input validation, which could allow a path traversal attack leading to potential privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to install a malicious ACAP application.
A path traversal vulnerability allowing potential privilege escalation has been identified in Axis devices running AXIS OS versions 12.0.0 through 12.10.3. The issue arises from an ACAP configuration file that lacked proper input validation, which could be exploited if the device is set to allow the installation of unsigned ACAP applications. An attacker would need to persuade a victim to install a malicious ACAP application for exploitation to occur.
Axis has released a patch for this vulnerability in AXIS OS Active Track 12.10.4. Devices not included in this track but still under support will receive a patch according to their planned maintenance and release schedule. It is recommended to update the device software to the latest version.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 12, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.axis.com/dam/public/51/64/ea/cve-2026-0804pdf-en-US-530732.pdf | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-35 | Path Traversal: '.../...//' | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| axis axis os | >= 12.0.0, < 12.10.4 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 19, 2026 | Initial Analysis | [email protected] |
| May 12, 2026 | New CVE Received | [email protected] |