CVE-2026-5304: Input Validation
An ACAP configuration file lacks input validation, which could potentially lead to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to install a malicious ACAP application.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
On the Axis device, disable the option that allows installation of unsigned ACAP applications so that unsigned/malicious ACAPs cannot be installed (exploit requires this configuration).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5304?
The severity of CVE-2026-5304 is categorized as medium with a score of 5.7.
How do I fix CVE-2026-5304?
To fix CVE-2026-5304, ensure that the Axis device is configured to disallow the installation of unsigned ACAP applications.
What does CVE-2026-5304 allow an attacker to do?
CVE-2026-5304 allows an attacker to potentially escalate privileges by exploiting a lack of input validation in ACAP configuration files.
What conditions must be met for CVE-2026-5304 to be exploited?
For CVE-2026-5304 to be exploited, the Axis device must allow the installation of unsigned ACAP applications and the attacker must convince the victim to install a malicious application.
Which devices are affected by CVE-2026-5304?
CVE-2026-5304 affects Axis devices that support ACAP application installation.