CVE-2026-1185

MEDIUM

Axis Communications AB Axis OS < 12.10.36 - Incorrect Permission Assignment for Critical Resource

Title source: rule
STIX 2.1

Description

A configuration file on the local file system had improper input validation which could allow code execution and potentially lead to privilege escalation. This vulnerability can only be exploited if an attacker can log in to the Axis device using SSH.

Scores

CVSS v3 5.4
EPSS 0.0023
EPSS Percentile 13.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-732
Status published
Products (2)
axis/axis_os 12.0.0 - 12.10.37
Axis Communications AB/AXIS OS 12.0.0 - 12.10.36
Published May 12, 2026
Tracked Since May 12, 2026