CVE-2026-19908 HIGH

CVE-2026-19908: PAX Technology Q80 XCB Daemon Missing Authentication Vulnerability

Vendor Pax Technology
Product Q80
Weakness CWE-306 · Missing auth
Published August 14, 2026
Last update August 17, 2026

CVSS base score

7.1/10
Attack vector Adjacent
Attack complexity Low
Privileges required None
User interaction None
Confidentiality High
Integrity Low

CVSS vector

CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

What the vulnerability does

01Description

PAX Technology Q80 XCB Daemon Missing Authentication Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information and modify configuration on affected installations of PAX Technology Q80. Authentication is not required to exploit this vulnerability. The specific flaw exists within the XCB daemon. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of root. Was ZDI-CAN-30584.

Key dates

02Disclosure timeline

August 14, 2026 CVE published
August 17, 2026 Record updated

Related vulnerabilities

04Related CVE