PatchSiren cyber security CVE debrief
CVE-2026-0804 Axis Communications AB CVE debrief
A path traversal vulnerability in Axis OS ACAP configuration file handling could allow privilege escalation when unsigned ACAP application installation is enabled. The vulnerability requires both administrative misconfiguration (allowing unsigned apps) and social engineering to install a malicious application. Axis has released patched firmware in version 12.10.4.
- Vendor
- Axis Communications AB
- Product
- AXIS OS
- CVSS
- MEDIUM 6.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-12
- Original CVE updated
- 2026-05-19
- Advisory published
- 2026-05-12
- Advisory updated
- 2026-05-19
Who should care
Axis network camera and device administrators, physical security teams, IoT security practitioners, and organizations deploying Axis surveillance infrastructure
Technical summary
CVE-2026-0804 is a path traversal vulnerability (CWE-35) in Axis OS affecting versions 12.0.0 through 12.10.3. The vulnerability exists in ACAP (Axis Camera Application Platform) configuration file handling, which lacks sufficient input validation. Exploitation requires the device to be configured to allow unsigned ACAP applications and requires an attacker to convince a victim to install a malicious ACAP application. Successful exploitation could lead to privilege escalation with local attack vector, low attack complexity, and high privileges required (CVSS 3.1: 6.7 MEDIUM). The vulnerability was patched in Axis OS 12.10.4.
Defensive priority
medium
Recommended defensive actions
- Upgrade Axis OS to version 12.10.4 or later
- Disable unsigned ACAP application installation in device configuration
- Restrict ACAP application installation to trusted administrators only
- Verify ACAP application signatures before installation
- Review installed ACAP applications for unauthorized or suspicious entries
Evidence notes
Vendor advisory confirms CWE-35 (Path Traversal) and CVSS 3.1 vector AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H. Affected versions: Axis OS 12.0.0 through 12.10.3. Fixed in 12.10.4.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-0804 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-0804
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-0804 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-0804
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://www.axis.com/dam/public/51/64/ea/cve-2026-0804pdf-en-US-530732.pdf
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.