Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-5304

Опубликовано: 11 авг. 2026
Источник: redhat
CVSS3: 5.7
EPSS Низкий

Описание

An ACAP configuration file lacks input validation, which could potentially lead to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to install a malicious ACAP application.

A flaw was found in Axis devices. An attacker could exploit a lack of input validation in an ACAP (AXIS Camera Application Platform) configuration file to achieve privilege escalation. This vulnerability requires the Axis device to be configured to allow unsigned ACAP applications, and an attacker must convince a victim to install a malicious ACAP application.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6axisOut of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-266
https://bugzilla.redhat.com/show_bug.cgi?id=2513779Axis: Axis: Privilege escalation via malicious ACAP application installation

EPSS

Процентиль: 14%
0.00232
Низкий

5.7 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.7
nvd
5 дней назад

An ACAP configuration file lacks input validation, which could potentially lead to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to install a malicious ACAP application.

CVSS3: 5.7
github
4 дня назад

An ACAP configuration file lacks input validation, which could potentially lead to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to install a malicious ACAP application.

EPSS

Процентиль: 14%
0.00232
Низкий

5.7 Medium

CVSS3