Medium severity5.1NVD Advisory· Published Aug 11, 2026
CVE-2026-6505
CVE-2026-6505
Description
The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race condition, which could potentially lead to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to install a malicious ACAP application.
Affected products
1Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.