CVE-2026-0802
6.0 MEDIUMAn ACAP configuration file lacked sufficient input validation, which could allow command injection and potentially lead to privilege esca...
Published: 2026-05-12 · Last updated: 2026-05-19
Severity and scoring
- CVSS
- 6.0 MEDIUM
- Vector
- CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
- CWE
- CWE-1287
Affected products
| Vendor | Product |
|---|---|
| axis | axis_os |
Description
An ACAP configuration file lacked sufficient input validation, which could allow command injection and potentially lead to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to install a malicious ACAP application.
Source: NVD
References
Related CVEs
Same vendor
- CVE-2026-1185 — A configuration file on the local file system had improper input validation which could allow code execution and potentially lead to priv... (5.4 MEDIUM)
- CVE-2026-0804 — An ACAP configuration file lacked sufficient input validation, which could allow a path traversal attack leading to potential privilege e... (6.7 MEDIUM)
- CVE-2026-0541 — ACAP applications can gain elevated privileges due to improper input validation during the installation process, potentially leading to p... (6.7 MEDIUM)
Same CWE
- CVE-2026-10825 — A denial-of-service vulnerability exists in the WebSocket API due to insufficient validation and handling of JSON-based requests
- CVE-2026-9753 — The $_internalApplyOplogUpdate aggregation pipeline stage can be used to execute a document diff containing a malformed binary diff to re... (8.1 HIGH)
- CVE-2026-9742 — When OIDC authentication is enabled in configuration, clients may set specific values in the "mechanism" parameter of the "authenticate" ... (7.5 HIGH)
- CVE-2026-11460 — A flaw has been found in Boost Serialization up to 1.91 (7.3 HIGH)
- CVE-2024-6858 — In Arista’s EOS when in 802.1X mode, multi-auth unauthenticated hosts might be allowed access to a switch port if there exists an EAPOL c... (6.5 MEDIUM)