CVE-2026-0802: Input Validation
An ACAP configuration file lacked sufficient input validation, which could allow command injection and potentially lead to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to install a malicious ACAP application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0802?
CVE-2026-0802 has a high severity due to its potential to allow command injection and privilege escalation.
How do I fix CVE-2026-0802?
To fix CVE-2026-0802, ensure that your Axis device is configured to disallow the installation of unsigned ACAP applications.
What can be exploited in CVE-2026-0802?
CVE-2026-0802 can be exploited to perform command injection if the ACAP configuration file lacks sufficient input validation.
What type of devices are affected by CVE-2026-0802?
CVE-2026-0802 affects Axis devices that support the ACAP (Axis Camera Application Platform) and allow unsigned application installations.
What are the potential consequences of CVE-2026-0802 exploitation?
Exploitation of CVE-2026-0802 can lead to unauthorized access and privilege escalation on the affected Axis device.