CVE-2026-6505
Received Received - Intake

TOCTOU Race Condition in ACAP Framework

Vulnerability report for CVE-2026-6505, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-11

Last updated on: 2026-08-11

Assigner: Axis Communications AB

Description

The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race condition, which could potentially lead to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces theΒ victim to install a malicious ACAP application.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-11
Last Modified
2026-08-11
Generated
2026-08-11
AI Q&A
2026-08-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
axis axis_os From 12.0.0 (inc) to 12.11.43 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-367 The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-6505 is a Time-of-Check to Time-of-Use (TOCTOU) race condition in the ACAP framework of Axis OS versions 12.0.0 through 12.11.43. This flaw could allow privilege escalation if an attacker tricks a victim into installing a malicious, unsigned ACAP application on a device configured to permit such installations.

Detection Guidance

Detecting this vulnerability requires checking if your Axis device is running a vulnerable OS version (12.0.0 to 12.11.43) and if unsigned ACAP applications are allowed. Use the Axis device web interface or SSH to check the OS version with commands like 'show version' or 'cat /etc/os-release'. Verify ACAP settings in the device configuration.

Impact Analysis

If exploited, this vulnerability could lead to privilege escalation on affected Axis devices. This means an attacker might gain higher-level access to the device, potentially allowing them to perform unauthorized actions or control the device.

Compliance Impact

This vulnerability does not directly affect compliance with standards like GDPR or HIPAA. It is a technical flaw in Axis OS that could allow privilege escalation if exploited, but no evidence suggests it impacts data protection or privacy requirements under these regulations.

Mitigation Strategies

Immediately update the Axis device to Active Track 12.11.44 or later. Disable the installation of unsigned ACAP applications in the device settings. Monitor Axis advisories for patches for unsupported devices. Contact Axis Technical Support if assistance is needed.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-6505. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart