CVE-2026-1185
MEDIUMAxis Communications AB Axis OS < 12.10.36 - Incorrect Permission Assignment for Critical Resource
Title source: ruleDescription
A configuration file on the local file system had improper input validation which could allow code execution and potentially lead to privilege escalation. This vulnerability can only be exploited if an attacker can log in to the Axis device using SSH.
References (1)
Core 1
Scores
CVSS v3
5.4
EPSS
0.0023
EPSS Percentile
13.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-732
Status
published
Products (2)
axis/axis_os
12.0.0 - 12.10.37
Axis Communications AB/AXIS OS
12.0.0 - 12.10.36
Published
May 12, 2026
Tracked Since
May 12, 2026