CVE-2026-5303
MEDIUM
NVD
CVSS Score
5.7
Severity
MEDIUM
Published
Aug 11, 2026
Vendor
unknown
Description
The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race condition, which could potentially lead to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces theΒ victim to install a malicious ACAP application.