Axis OS

Axis · 56 CVEs

CVE-2026-4757
HIGH

Axis: Axis: Code execution and privilege escalation via VAPIX API improper input validation

Aug 11, 2026

CVE-2026-6505
MEDIUM

The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race condition, which could potentially lead to pri…

Aug 11, 2026

CVE-2026-5304
MEDIUM

Axis: Axis: Privilege escalation via malicious ACAP application installation

Aug 11, 2026

CVE-2026-5303
MEDIUM

The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race condition, which could potentially lead to pri…

Aug 11, 2026

CVE-2026-6181
MEDIUM

The Device Configuration Framework is vulnerable to an authentication bypass flaw. This flaw can only be exploited afte…

Aug 11, 2026

CVE-2026-1185
HIGH

A configuration file on the local file system had improper input validation which could allow code execution and potent…

May 12, 2026

CVE-2026-0804
HIGH

An ACAP configuration file lacked sufficient input validation, which could allow a path traversal attack leading to pot…

May 12, 2026

CVE-2026-0802
HIGH

An ACAP configuration file lacked sufficient input validation, which could allow command injection and potentially lead…

May 12, 2026

CVE-2026-0541
HIGH

ACAP applications can gain elevated privileges due to improper input validation during the installation process, potent…

May 12, 2026

CVE-2025-11142
HIGH

The VAPIX API mediaclip.cgi that did not have a sufficient input validation allowing for a possible remote code executi…

Feb 10, 2026

CVE-2025-9055
MEDIUM

The VAPIX Edge storage API that allowed a privilege escalation, enabling a VAPIX administrator-privileged user to gain…

Nov 11, 2025

CVE-2025-8998
LOW

It was possible to upload files with a specific name to a temporary directory, which may result in process crashes and…

Nov 11, 2025

CVE-2025-9524
MEDIUM

The VAPIX API port.cgi did not have sufficient input validation, which may result in process crashes and impact usabili…

Nov 11, 2025

CVE-2025-8108
MEDIUM

An ACAP configuration file has improper permissions and lacks input validation, which could potentially lead to privile…

Nov 11, 2025

CVE-2025-6779
MEDIUM

An ACAP configuration file has improper permissions, which could allow command injection and potentially lead to privil…

Nov 11, 2025

CVE-2025-6571
MEDIUM

A 3rd-party component exposed its password in process arguments, allowing for low-privileged users to access it.

Nov 11, 2025

CVE-2025-5452
MEDIUM

A malicious ACAP application can gain access to admin-level service account credentials used by legitimate ACAP applica…

Nov 11, 2025

CVE-2025-6298
MEDIUM

ACAP applications can gain elevated privileges due to improper input validation, potentially leading to privilege escal…

Nov 11, 2025

CVE-2025-5718
MEDIUM

The ACAP Application framework could allow privilege escalation through a symlink attack. This vulnerability can only b…

Nov 11, 2025

CVE-2025-5454
MEDIUM

An ACAP configuration file lacked sufficient input validation, which could allow a path traversal attack leading to pot…

Nov 11, 2025

CVE-2025-4645
MEDIUM

An ACAP configuration file lacked sufficient input validation, which could allow for arbitrary code execution. This vul…

Nov 11, 2025

CVE-2025-30027
MEDIUM

An ACAP configuration file lacked sufficient input validation, which could allow for arbitrary code execution. This vul…

Aug 12, 2025

CVE-2025-3892
MEDIUM

ACAP applications can be executed with elevated privileges, potentially leading to privilege escalation. This vulnerabi…

Aug 12, 2025

CVE-2025-0358
HIGH

During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the VAPIX Dev…

Jun 2, 2025

CVE-2025-0325
MEDIUM

A Guard Tour VAPIX API parameter allowed the use of arbitrary values and can be incorrectly called, allowing an attacke…

Jun 2, 2025

Showing 1 to 25 of 56 CVEs