A Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection. Six years running.Six years. Gartner® Magic Quadrant™ Leader.Find Out Why
Experiencing a Breach?Blog
Get StartedContact Us
SentinelOne
  • Platform
    Platform Overview
    • Singularity Platform
      Welcome to Integrated Enterprise Security
    • AI for Security
      Leading the Way in AI-Powered Security Solutions
    • Securing AI
      Accelerate AI Adoption with Secure AI Tools, Apps, and Agents.
    • How It Works
      The Singularity XDR Difference
    • Singularity Marketplace
      One-Click Integrations to Unlock the Power of XDR
    • Pricing & Packaging
      Comparisons and Guidance at a Glance
    Data & AI
    • Purple AI
      Accelerate SecOps with Generative AI
    • Singularity Hyperautomation
      Easily Automate Security Processes
    • AI-SIEM
      The AI SIEM for the Autonomous SOC
    • AI Data Pipelines
      Security Data Pipeline for AI SIEM and Data Optimization
    • Singularity Data Lake
      AI-Powered, Unified Data Lake
    • Singularity Data Lake for Log Analytics
      Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
    Endpoint Security
    • Singularity Endpoint
      Autonomous Prevention, Detection, and Response
    • Singularity XDR
      Native & Open Protection, Detection, and Response
    • Singularity RemoteOps Forensics
      Orchestrate Forensics at Scale
    • Singularity Threat Intelligence
      Comprehensive Adversary Intelligence
    • Singularity Vulnerability Management
      Application & OS Vulnerability Management
    • Singularity Identity
      Identity Threat Detection and Response
    Cloud Security
    • Singularity Cloud Security
      Block Attacks with an AI-Powered CNAPP
    • Singularity Cloud Native Security
      Secure Cloud and Development Resources
    • Singularity Cloud Workload Security
      Real-Time Cloud Workload Protection Platform
    • Singularity Cloud Data Security
      AI-Powered Threat Detection for Cloud Storage
    • Singularity Cloud Security Posture Management
      Detect and Remediate Cloud Misconfigurations
    Securing AI
    • Prompt Security
      Secure AI Tools Across Your Enterprise
  • Why SentinelOne?
    Why SentinelOne?
    • Why SentinelOne?
      Cybersecurity Built for What’s Next
    • Our Customers
      Trusted by the World’s Leading Enterprises
    • Industry Recognition
      Tested and Proven by the Experts
    • About Us
      The Industry Leader in Autonomous Cybersecurity
    Compare SentinelOne
    • Arctic Wolf
    • Broadcom
    • CrowdStrike
    • Cybereason
    • Microsoft
    • Palo Alto Networks
    • Sophos
    • Splunk
    • Trellix
    • Trend Micro
    • Wiz
    Verticals
    • Energy
    • Federal Government
    • Finance
    • Healthcare
    • Higher Education
    • K-12 Education
    • Manufacturing
    • Retail
    • State and Local Government
  • Services
    Managed Services
    • Managed Services Overview
      Wayfinder Threat Detection & Response
    • Threat Hunting
      World-Class Expertise and Threat Intelligence
    • Managed Detection & Response
      24/7/365 Expert MDR Across Your Entire Environment
    • Incident Readiness & Response
      DFIR, Breach Readiness, & Compromise Assessments
    Support, Deployment, & Health
    • Technical Account Management
      Customer Success with Personalized Service
    • SentinelOne GO
      Guided Onboarding & Deployment Advisory
    • SentinelOne University
      Live and On-Demand Training
    • Services Overview
      Comprehensive Solutions for Seamless Security Operations
    • SentinelOne Community
      Community Login
  • Partners
    Our Network
    • MSSP Partners
      Succeed Faster with SentinelOne
    • Singularity Marketplace
      Extend the Power of S1 Technology
    • Cyber Risk Partners
      Enlist Pro Response and Advisory Teams
    • Technology Alliances
      Integrated, Enterprise-Scale Solutions
    • SentinelOne for AWS
      Hosted in AWS Regions Around the World
    • Channel Partners
      Deliver the Right Solutions, Together
    • SentinelOne for Google Cloud
      Unified, Autonomous Security Giving Defenders the Advantage at Global Scale
    • Partner Locator
      Your Go-to Source for Our Top Partners in Your Region
    Partner Portal→
  • Resources
    Resource Center
    • Case Studies
    • Data Sheets
    • eBooks
    • Reports
    • Videos
    • Webinars
    • Whitepapers
    • Events
    View All Resources→
    Blog
    • Feature Spotlight
    • For CISO/CIO
    • From the Front Lines
    • Identity
    • Cloud
    • macOS
    • SentinelOne Blog
    Blog→
    Tech Resources
    • SentinelLABS
    • Ransomware Anthology
    • Cybersecurity 101
  • About
    About SentinelOne
    • About SentinelOne
      The Industry Leader in Cybersecurity
    • Investor Relations
      Financial Information & Events
    • SentinelLABS
      Threat Research for the Modern Threat Hunter
    • Careers
      The Latest Job Opportunities
    • Press & News
      Company Announcements
    • Cybersecurity Blog
      The Latest Cybersecurity Threats, News, & More
    • FAQ
      Get Answers to Our Most Frequently Asked Questions
    • DataSet
      The Live Data Platform
    • S Foundation
      Securing a Safer Future for All
    • S Ventures
      Investing in the Next Generation of Security, Data and AI
  • Pricing
Get StartedContact Us
CVE Vulnerability Database
Vulnerability Database/CVE-2026-0802

CVE-2026-0802: Axis ACAP Privilege Escalation Vulnerability

CVE-2026-0802 is a privilege escalation flaw in Axis ACAP configuration files that allows command injection through malicious applications. This article covers the technical details, affected versions, and mitigation.

Published: May 18, 2026

CVE-2026-0802 Overview

CVE-2026-0802 affects Axis network devices that support ACAP (AXIS Camera Application Platform) applications. An ACAP configuration file lacks sufficient input validation, allowing command injection that can lead to privilege escalation on the device. Exploitation requires two preconditions: the device must permit installation of unsigned ACAP applications, and an attacker must persuade the victim to install a malicious ACAP package. The weakness is classified as [CWE-1287] Improper Validation of Specified Type of Input. Axis published a security advisory on May 12, 2026 documenting the issue and remediation guidance.

Critical Impact

A malicious ACAP application can inject commands through an unvalidated configuration file and escalate privileges on the affected Axis device.

Affected Products

  • Axis network devices supporting ACAP applications (see vendor advisory for specific firmware versions)
  • Devices configured to allow installation of unsigned ACAP applications
  • Refer to the Axis Security Advisory CVE-2026-0802 for the complete model and firmware list

Discovery Timeline

  • 2026-05-12 - CVE-2026-0802 published to NVD
  • 2026-05-12 - Last updated in NVD database

Technical Details for CVE-2026-0802

Vulnerability Analysis

The vulnerability resides in how an ACAP configuration file is parsed and consumed on Axis devices. The configuration file is processed without adequate validation of input fields, allowing an attacker to embed shell metacharacters or command sequences. When the device processes the configuration values, the injected content is executed in the context of a higher-privileged process. This combination of weak input validation and unsafe command execution maps directly to [CWE-1287].

Because the attack vector is local and requires high privileges to install applications, the threat model centers on a device operator who has been socially engineered into deploying a malicious ACAP package. Successful exploitation yields elevated privileges on the device, compromising confidentiality and integrity of video feeds, credentials, and system configuration.

Root Cause

The ACAP configuration parser trusts attacker-influenced strings and passes them to a command interpreter without sanitization or argument separation. Missing allowlist validation on configuration keys and values permits injection of arbitrary commands during configuration load or apply operations.

Attack Vector

An attacker first crafts a malicious ACAP application containing a weaponized configuration file. The attacker then convinces a device administrator to enable unsigned ACAP installation and deploy the package. During configuration processing, the injected commands execute with elevated privileges, granting the attacker control over the device. Exploitation is not possible on devices that retain the default policy of accepting only signed ACAP applications.

No public proof-of-concept code is available. Technical specifics are limited to those described in the Axis Security Advisory CVE-2026-0802.

Detection Methods for CVE-2026-0802

Indicators of Compromise

  • Presence of unsigned or unexpected ACAP applications on Axis devices
  • ACAP configuration files containing shell metacharacters such as ;, |, `, $(, or newline-separated commands
  • Unexplained child processes spawned by the ACAP runtime or device management daemon
  • Outbound network connections from the device to unknown hosts following an ACAP installation event

Detection Strategies

  • Inventory all installed ACAP applications and verify each is signed and sourced from a trusted publisher
  • Audit device settings to confirm whether unsigned ACAP installation is enabled, and treat any device with this setting as higher risk
  • Compare deployed ACAP package hashes against a known-good baseline maintained by the security team
  • Review device system logs for configuration apply events that precede anomalous process activity

Monitoring Recommendations

  • Forward Axis device syslog to a centralized logging platform and alert on ACAP install, uninstall, and configuration change events
  • Monitor administrative access to the Axis web interface and VAPI endpoints used for ACAP management
  • Track network egress from camera VLANs to identify post-exploitation command-and-control activity

How to Mitigate CVE-2026-0802

Immediate Actions Required

  • Disable installation of unsigned ACAP applications on all Axis devices through the device configuration
  • Remove any ACAP applications that are not required for business operations or whose provenance is unverified
  • Restrict administrative access to Axis devices using network segmentation and strong authentication
  • Apply the firmware update referenced in the Axis advisory once available for the affected device model

Patch Information

Axis has published remediation guidance in the Axis Security Advisory CVE-2026-0802. Administrators should consult the advisory for the patched firmware version applicable to their device model and apply the update through the standard Axis firmware upgrade process.

Workarounds

  • Enforce the default Axis policy that permits only signed ACAP applications from trusted publishers
  • Place Axis devices on an isolated management VLAN that blocks inbound access from general user networks
  • Require multi-person approval for any ACAP installation in production environments
bash
# Configuration example: verify and disable unsigned ACAP installation via VAPI
# Query current allow-unsigned setting
curl -u admin:PASSWORD --digest \
  "https://CAMERA_IP/axis-cgi/param.cgi?action=list&group=Network.ACAP.AllowUnsigned"

# Disable unsigned ACAP installation
curl -u admin:PASSWORD --digest \
  "https://CAMERA_IP/axis-cgi/param.cgi?action=update&Network.ACAP.AllowUnsigned=no"

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

  • Vulnerability Details
  • TypePrivilege Escalation

  • Vendor/TechAxis

  • SeverityMEDIUM

  • CVSS Score6.0

  • EPSS Probability0.04%

  • Known ExploitedNo
  • CVSS Vector
  • CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
  • Impact Assessment
  • ConfidentialityLow
  • IntegrityNone
  • AvailabilityNone
  • CWE References
  • CWE-1287
  • Technical References
  • Axis Security Advisory CVE-2026-0802
  • Related CVEs
  • CVE-2026-0541: ACAP Privilege Escalation Vulnerability

  • CVE-2026-1185: Axis Device Privilege Escalation Flaw

  • CVE-2026-0804: Axis ACAP Privilege Escalation Vulnerability

  • CVE-2025-0325: Axis Guard Tour VAPIX API DoS Vulnerability
Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.

Try SentinelOne
  • Get Started
  • Get a Demo
  • Product Tour
  • Why SentinelOne
  • Pricing & Packaging
  • FAQ
  • Contact
  • Contact Us
  • Customer Support
  • SentinelOne Status
  • Language
  • Platform
  • Singularity Platform
  • Singularity Endpoint
  • Singularity Cloud
  • Singularity AI-SIEM
  • Singularity Identity
  • Singularity Marketplace
  • Purple AI
  • Services
  • Wayfinder TDR
  • SentinelOne GO
  • Technical Account Management
  • Support Services
  • Verticals
  • Energy
  • Federal Government
  • Finance
  • Healthcare
  • Higher Education
  • K-12 Education
  • Manufacturing
  • Retail
  • State and Local Government
  • Cybersecurity for SMB
  • Resources
  • Blog
  • Labs
  • Case Studies
  • Videos
  • Product Tours
  • Events
  • Cybersecurity 101
  • eBooks
  • Webinars
  • Whitepapers
  • Press
  • News
  • Ransomware Anthology
  • Company
  • About Us
  • Our Customers
  • Careers
  • Partners
  • Legal & Compliance
  • Security & Compliance
  • Investor Relations
  • S Foundation
  • S Ventures

©2026 SentinelOne, All Rights Reserved.

Privacy Notice Terms of Use

English