Axis OS
Axis · 56 CVEs
Axis: Axis: Code execution and privilege escalation via VAPIX API improper input validation
Aug 11, 2026
The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race condition, which could potentially lead to pri…
Aug 11, 2026
Axis: Axis: Privilege escalation via malicious ACAP application installation
Aug 11, 2026
The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race condition, which could potentially lead to pri…
Aug 11, 2026
The Device Configuration Framework is vulnerable to an authentication bypass flaw. This flaw can only be exploited afte…
Aug 11, 2026
A configuration file on the local file system had improper input validation which could allow code execution and potent…
May 12, 2026
An ACAP configuration file lacked sufficient input validation, which could allow a path traversal attack leading to pot…
May 12, 2026
An ACAP configuration file lacked sufficient input validation, which could allow command injection and potentially lead…
May 12, 2026
ACAP applications can gain elevated privileges due to improper input validation during the installation process, potent…
May 12, 2026
The VAPIX API mediaclip.cgi that did not have a sufficient input validation allowing for a possible remote code executi…
Feb 10, 2026
The VAPIX Edge storage API that allowed a privilege escalation, enabling a VAPIX administrator-privileged user to gain…
Nov 11, 2025
It was possible to upload files with a specific name to a temporary directory, which may result in process crashes and…
Nov 11, 2025
The VAPIX API port.cgi did not have sufficient input validation, which may result in process crashes and impact usabili…
Nov 11, 2025
An ACAP configuration file has improper permissions and lacks input validation, which could potentially lead to privile…
Nov 11, 2025
An ACAP configuration file has improper permissions, which could allow command injection and potentially lead to privil…
Nov 11, 2025
A 3rd-party component exposed its password in process arguments, allowing for low-privileged users to access it.
Nov 11, 2025
A malicious ACAP application can gain access to admin-level service account credentials used by legitimate ACAP applica…
Nov 11, 2025
ACAP applications can gain elevated privileges due to improper input validation, potentially leading to privilege escal…
Nov 11, 2025
The ACAP Application framework could allow privilege escalation through a symlink attack. This vulnerability can only b…
Nov 11, 2025
An ACAP configuration file lacked sufficient input validation, which could allow a path traversal attack leading to pot…
Nov 11, 2025
An ACAP configuration file lacked sufficient input validation, which could allow for arbitrary code execution. This vul…
Nov 11, 2025
An ACAP configuration file lacked sufficient input validation, which could allow for arbitrary code execution. This vul…
Aug 12, 2025
ACAP applications can be executed with elevated privileges, potentially leading to privilege escalation. This vulnerabi…
Aug 12, 2025
During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the VAPIX Dev…
Jun 2, 2025
A Guard Tour VAPIX API parameter allowed the use of arbitrary values and can be incorrectly called, allowing an attacke…
Jun 2, 2025
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-4757 | Axis: Axis: Code execution and privilege escalation via VAPIX API improper input validation | HIGH | 0.57% | Aug 11, 2026 |
| CVE-2026-6505 | The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race condition, which could potentially lead to privilege escalation. This vulnerability ca… | MEDIUM | 0.09% | Aug 11, 2026 |
| CVE-2026-5304 | Axis: Axis: Privilege escalation via malicious ACAP application installation | MEDIUM | 0.31% | Aug 11, 2026 |
| CVE-2026-5303 | The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race condition, which could potentially lead to privilege escalation. This vulnerability ca… | MEDIUM | 0.23% | Aug 11, 2026 |
| CVE-2026-6181 | The Device Configuration Framework is vulnerable to an authentication bypass flaw. This flaw can only be exploited after authenticating with a viewer-privilege… | MEDIUM | 0.39% | Aug 11, 2026 |
| CVE-2026-1185 | A configuration file on the local file system had improper input validation which could allow code execution and potentially lead to privilege escalation. This… | HIGH | 0.23% | May 12, 2026 |
| CVE-2026-0804 | An ACAP configuration file lacked sufficient input validation, which could allow a path traversal attack leading to potential privilege escalation. This vulner… | HIGH | 0.13% | May 12, 2026 |
| CVE-2026-0802 | An ACAP configuration file lacked sufficient input validation, which could allow command injection and potentially lead to privilege escalation. This vulnerabi… | HIGH | 0.40% | May 12, 2026 |
| CVE-2026-0541 | ACAP applications can gain elevated privileges due to improper input validation during the installation process, potentially leading to privilege escalation. T… | HIGH | 0.10% | May 12, 2026 |
| CVE-2025-11142 | The VAPIX API mediaclip.cgi that did not have a sufficient input validation allowing for a possible remote code execution. This flaw can only be exploited afte… | HIGH | 0.53% | Feb 10, 2026 |
| CVE-2025-9055 | The VAPIX Edge storage API that allowed a privilege escalation, enabling a VAPIX administrator-privileged user to gain Linux Root privileges. This flaw can onl… | MEDIUM | 0.11% | Nov 11, 2025 |
| CVE-2025-8998 | It was possible to upload files with a specific name to a temporary directory, which may result in process crashes and impact usability. This flaw can only be… | LOW | 0.22% | Nov 11, 2025 |
| CVE-2025-9524 | The VAPIX API port.cgi did not have sufficient input validation, which may result in process crashes and impact usability. This vulnerability can only be explo… | MEDIUM | 0.25% | Nov 11, 2025 |
| CVE-2025-8108 | An ACAP configuration file has improper permissions and lacks input validation, which could potentially lead to privilege escalation. This vulnerability can on… | MEDIUM | 0.13% | Nov 11, 2025 |
| CVE-2025-6779 | An ACAP configuration file has improper permissions, which could allow command injection and potentially lead to privilege escalation. This vulnerability can o… | MEDIUM | 1.07% | Nov 11, 2025 |
| CVE-2025-6571 | A 3rd-party component exposed its password in process arguments, allowing for low-privileged users to access it. | MEDIUM | 0.11% | Nov 11, 2025 |
| CVE-2025-5452 | A malicious ACAP application can gain access to admin-level service account credentials used by legitimate ACAP applications, leading to potential privilege es… | MEDIUM | 0.29% | Nov 11, 2025 |
| CVE-2025-6298 | ACAP applications can gain elevated privileges due to improper input validation, potentially leading to privilege escalation. This vulnerability can only be ex… | MEDIUM | 0.14% | Nov 11, 2025 |
| CVE-2025-5718 | The ACAP Application framework could allow privilege escalation through a symlink attack. This vulnerability can only be exploited if the Axis device is config… | MEDIUM | 0.36% | Nov 11, 2025 |
| CVE-2025-5454 | An ACAP configuration file lacked sufficient input validation, which could allow a path traversal attack leading to potential privilege escalation. This vulner… | MEDIUM | 0.15% | Nov 11, 2025 |
| CVE-2025-4645 | An ACAP configuration file lacked sufficient input validation, which could allow for arbitrary code execution. This vulnerability can only be exploited if the… | MEDIUM | 0.15% | Nov 11, 2025 |
| CVE-2025-30027 | An ACAP configuration file lacked sufficient input validation, which could allow for arbitrary code execution. This vulnerability can only be exploited if the… | MEDIUM | 0.16% | Aug 12, 2025 |
| CVE-2025-3892 | ACAP applications can be executed with elevated privileges, potentially leading to privilege escalation. This vulnerability can only be exploited if the Axis d… | MEDIUM | 0.15% | Aug 12, 2025 |
| CVE-2025-0358 | During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the VAPIX Device Configuration framework that allowed… | HIGH | 0.25% | Jun 2, 2025 |
| CVE-2025-0325 | A Guard Tour VAPIX API parameter allowed the use of arbitrary values and can be incorrectly called, allowing an attacker to block access to the guard tour conf… | MEDIUM | 0.38% | Jun 2, 2025 |
Showing 1 to 25 of 56 CVEs