CVE-2026-19908
Received Received - Intake

XCB Daemon Missing Authentication in PAX Technology Q80

Vulnerability report for CVE-2026-19908, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-14

Last updated on: 2026-08-14

Assigner: Zero Day Initiative

Description

PAX Technology Q80 XCB Daemon Missing Authentication Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information and modify configuration on affected installations of PAX Technology Q80. Authentication is not required to exploit this vulnerability. The specific flaw exists within the XCB daemon. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of root. Was ZDI-CAN-30584.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-14
Last Modified
2026-08-14
Generated
2026-08-15
AI Q&A
2026-08-14
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
pax_technology q80 *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-19908 is a missing authentication vulnerability in PAX Technology's Q80 device, specifically in the XCB daemon. It allows network-adjacent attackers to access sensitive information and modify configurations without authentication. This flaw can be combined with other vulnerabilities to execute arbitrary code as root.

Detection Guidance

Detecting this vulnerability requires checking for open ports and services associated with the PAX Technology Q80 XCB daemon. Use network scanning tools like nmap to identify if the device is exposed on the network. Commands like 'nmap -p 1-65535 -sV <target_IP>' can help identify open ports and service versions. Additionally, inspect network traffic for unauthenticated access attempts to the XCB daemon.

Impact Analysis

This vulnerability allows attackers to disclose sensitive data and alter device configurations remotely. If exploited with other flaws, it could enable arbitrary code execution with root privileges, leading to full system compromise.

Mitigation Strategies

Immediate mitigation involves restricting network access to the PAX Technology Q80 device. Isolate the device from untrusted networks, disable unnecessary services, and implement strict firewall rules to block unauthorized access. Since the firmware is end-of-life and unsupported, updating is not an option. Regularly monitor network traffic for suspicious activity targeting the XCB daemon.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19908. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart