CVE-2026-6181

Summary

The Device Configuration Framework is vulnerable to an authentication bypass flaw. This flaw can only be exploited after authenticating with a viewer-privileged service account.

Affected Software

VendorProductVersion RangeStatus
Axis Communications ABAXIS OS12.0.0 < 12.11.13affected
Axis Communications ABAXIS OS11.11.0 < 11.11.207affected

Weaknesses

  • CWE-290: CWE-290: Authentication Bypass by Spoofing

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References