PatchSiren cyber security CVE debrief
CVE-2026-0802 Axis Communications AB CVE debrief
An ACAP configuration file in Axis OS lacked sufficient input validation, enabling command injection and potential privilege escalation. Exploitation requires the device to permit unsigned ACAP application installation and user installation of a malicious application.
- Vendor
- Axis Communications AB
- Product
- AXIS OS
- CVSS
- MEDIUM 6
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-12
- Original CVE updated
- 2026-05-19
- Advisory published
- 2026-05-12
- Advisory updated
- 2026-05-19
Who should care
Organizations deploying Axis network cameras or video encoders with ACAP application support enabled, particularly those in critical infrastructure, surveillance, or physical security environments where device integrity is essential.
Technical summary
The vulnerability exists in ACAP (Axis Camera Application Platform) configuration file processing, where insufficient input validation allows command injection. Attack vector is local with high privileges required, but successful exploitation yields high confidentiality and integrity impact. The attack chain requires: (1) device configured to allow unsigned ACAP applications, and (2) social engineering to install malicious ACAP package.
Defensive priority
medium
Recommended defensive actions
- Restrict ACAP application installation to signed applications only via device configuration policies.
- Upgrade Axis OS to version 12.9.33 or later where this vulnerability is remediated.
- Audit installed ACAP applications and remove any unauthorized or unsigned packages.
- Monitor device logs for anomalous command execution or privilege escalation indicators.
Evidence notes
CVE published 2026-05-12; modified 2026-05-19. Vendor advisory confirms affected versions and remediation. CVSS 3.1 vector: AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-0802 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-0802
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-0802 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-0802
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://www.axis.com/dam/public/67/b8/75/cve-2026-0802pdf-en-US-530731.pdf
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.