CVE-2026-0804: Input Validation
An ACAP configuration file lacked sufficient input validation, which could allow a path traversal attack leading to potential privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to install a malicious ACAP application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0804?
CVE-2026-0804 is a high severity vulnerability due to its potential for privilege escalation via path traversal.
How do I fix CVE-2026-0804?
To mitigate CVE-2026-0804, ensure that the device is configured to disallow the installation of unsigned ACAP applications.
What systems are affected by CVE-2026-0804?
CVE-2026-0804 affects the Axis Camera Application Platform (ACAP) if configured to permit unsigned applications.
Can CVE-2026-0804 be exploited remotely?
Yes, CVE-2026-0804 can be exploited remotely if the correct conditions regarding the configuration are met.
What type of attack does CVE-2026-0804 facilitate?
CVE-2026-0804 facilitates a path traversal attack that could lead to privilege escalation on the affected system.