QSearchQSearch

CVE-2026-0802

6.0 MEDIUM

An ACAP configuration file lacked sufficient input validation, which could allow command injection and potentially lead to privilege esca...

Published: 2026-05-12 · Last updated: 2026-05-19

Severity and scoring

CVSS
6.0 MEDIUM
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
CWE
CWE-1287

Affected products

VendorProduct
axisaxis_os

Description

An ACAP configuration file lacked sufficient input validation, which could allow command injection and potentially lead to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to install a malicious ACAP application.

Source: NVD

References

Related CVEs

Same vendor

  • CVE-2026-1185 A configuration file on the local file system had improper input validation which could allow code execution and potentially lead to priv... (5.4 MEDIUM)
  • CVE-2026-0804 An ACAP configuration file lacked sufficient input validation, which could allow a path traversal attack leading to potential privilege e... (6.7 MEDIUM)
  • CVE-2026-0541 ACAP applications can gain elevated privileges due to improper input validation during the installation process, potentially leading to p... (6.7 MEDIUM)

Same CWE

  • CVE-2026-10825 A denial-of-service vulnerability exists in the WebSocket API due to insufficient validation and handling of JSON-based requests
  • CVE-2026-9753 The $_internalApplyOplogUpdate aggregation pipeline stage can be used to execute a document diff containing a malformed binary diff to re... (8.1 HIGH)
  • CVE-2026-9742 When OIDC authentication is enabled in configuration, clients may set specific values in the "mechanism" parameter of the "authenticate" ... (7.5 HIGH)
  • CVE-2026-11460 A flaw has been found in Boost Serialization up to 1.91 (7.3 HIGH)
  • CVE-2024-6858 In Arista’s EOS when in 802.1X mode, multi-auth unauthenticated hosts might be allowed access to a switch port if there exists an EAPOL c... (6.5 MEDIUM)