CVE-2026-5303
Received Received - Intake

TOCTOU Race Condition in ACAP Framework

Vulnerability report for CVE-2026-5303, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-11

Last updated on: 2026-08-11

Assigner: Axis Communications AB

Description

The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race condition, which could potentially lead to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces theΒ victim to install a malicious ACAP application.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-11
Last Modified
2026-08-11
Generated
2026-08-11
AI Q&A
2026-08-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
axis axis_os From 12.0.0 (inc) to 12.11.30 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-367 The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-5303 is a Time-of-Check to Time-of-Use (TOCTOU) race condition in the ACAP framework of Axis OS versions 12.0.0 through 12.11.30. This flaw could allow privilege escalation if an attacker tricks a user into installing a malicious, unsigned ACAP application on a device configured to permit such installations.

Detection Guidance

Detecting this vulnerability requires checking Axis OS versions and ACAP application settings. Verify if your device runs Axis OS 12.0.0 through 12.11.30 using the device web interface or command line. Check if unsigned ACAP applications are allowed in the ACAP settings. Commands may include checking OS version via 'show version' or similar, and reviewing ACAP configuration settings.

Impact Analysis

If exploited, this vulnerability could allow an attacker to gain elevated privileges on an affected Axis device. This requires the device to be configured to allow unsigned ACAP applications and the victim to install a malicious application.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR or HIPAA as it involves a technical flaw in Axis OS ACAP framework allowing privilege escalation via malicious unsigned ACAP applications. Compliance impact would depend on whether the affected device processes or stores regulated data and if proper security controls are implemented to mitigate risks.

Mitigation Strategies

Immediately update Axis OS to version 12.11.31 or later. Disable the installation of unsigned ACAP applications if not required. Monitor Axis security advisories for further updates and apply patches as they become available for other supported devices.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-5303. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart