MEDIUMVulnerability
CVE-2026-6505
The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race condition, which could potentially lead to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to install a malicious ACAP application.
Properties
- severity
- MEDIUM
- score
- 5.1
- epss_score
- 0.00074
- cve_id
- CVE-2026-6505
- vector
- CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:L/A:L
- published_at
- 2026-08-11T06:17:16.970
- last_modified
- 2026-09-03T16:44:01.873
- epss_percentile
- 0.00073
Related Entities (3)
ENRICHED_BY (1)
→[Source]FIRST EPSS
DESCRIBED_BY (1)
→[Source]NVD
HAS_WEAKNESS (1)
→[Weakness]Time-of-check Time-of-use (TOCTOU) Race Condition
Explore deeper with Ninja Signal's threat intelligence graph