Loading HuntDB...

GHSA-5ww9-v6r8-v66v

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

A malicious ACAP application can gain access to admin-level service account credentials used by legitimate ACAP applications, leading to potential privilege escalation of the malicious ACAP application. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to install a malicious ACAP application.

Related CVEs

Key Information

GHSA ID
GHSA-5ww9-v6r8-v66v
Published
November 11, 2025 9:30 AM
Last Modified
November 11, 2025 9:30 AM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: November 26, 2025 6:30 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.