What is CVE-2026-5304?
CVE-2026-5304 is a vulnerability in Axis devices where an ACAP configuration file lacks input validation, potentially leading to privilege escalation. This flaw is exploitable only if unsigned ACAP application installation is allowed and an attacker convinces a victim to install a malicious ACAP app. Users should ensure only signed ACAP applications are installed.
Azərbaycanca: CVE-2026-5304 Axis cihazlarında ACAP konfiqurasiya faylında daxiletmə doğrulamasının olmaması ilə əlaqədardır ki, bu da imzasız ACAP tətbiqlərin quraşdırılmasına icazə verilərsə, imtiyaz artımına səbəb ola bilər. Zəiflik yalnız zərərçəkən şəxsin zərərli ACAP tətbiqini quraşdırması ilə istismar edilə bilər. İstifadəçilərə yalnız imzalanmış ACAP tətbiqləri quraşdırmaq tövsiyə olunur.
FAQ2
What must an attacker do to exploit the CVE-2026-5304 vulnerability?
The flaw is exploitable only if unsigned ACAP application installation is allowed and the attacker convinces a victim to install a malicious ACAP app.
What is recommended for users to protect against CVE-2026-5304?
Users should ensure only signed ACAP applications are installed.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.