MEDIUMVulnerability

CVE-2026-6505

The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race condition, which could potentially lead to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to install a malicious ACAP application.

Properties

severity
MEDIUM
score
5.1
epss_score
0.00074
cve_id
CVE-2026-6505
vector
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:L/A:L
published_at
2026-08-11T06:17:16.970
last_modified
2026-09-03T16:44:01.873
epss_percentile
0.00073

Related Entities (3)

ENRICHED_BY (1)

[Source]FIRST EPSS

DESCRIBED_BY (1)

[Source]NVD

HAS_WEAKNESS (1)

[Weakness]Time-of-check Time-of-use (TOCTOU) Race Condition

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-6505 — Ninja Signal Threat Intelligence | Ninja Signal