CVE-2026-5304: Input Validation
An ACAP configuration file lacks input validation, which could potentially lead to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to install a malicious ACAP application.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
On the Axis device, disable the option that allows installation of unsigned ACAP applications so that unsigned/malicious ACAPs cannot be installed (exploit requires this configuration).