CVE-2026-1185
published 2026-05-12CVE-2026-1185: A configuration file on the local file system had improper input validation which could allow code execution and potentially lead to privilege escalation. This…
PriorityP355high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.23%
13.3th percentile
A configuration file on the local file system had improper input validation which could allow code execution and potentially lead to privilege escalation. This vulnerability can only be exploited if an attacker can log in to the Axis device using SSH.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| axis | axis_os | >= 12.0.0 < 12.10.37 | 12.10.37 |
| axis_communications_ab | axis_os | >= 12.0.0 < 12.10.36 | 12.10.36 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-05-12
Published