PT-2026-70070 · Axis Communications · Acap

·

CVE-2026-5304

·

Published

2026-08-11

·

Updated

2026-08-11

CVSS v3.1

5.7

Medium

VectorAV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Axis Communications ACAP (affected versions not specified)
Description An ACAP configuration file lacks input validation, which could potentially lead to privilege escalation. This issue is exploitable only if the device is configured to allow the installation of unsigned ACAP applications and a user is convinced to install a malicious ACAP application.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-5304

Affected Products

Acap