Junglewise Threat Intelligence

CVE-2026-19908: PAX Technology Q80 XCB Daemon missing authentication

CVE-2026-19908 · Severity: high · CVSS 7.1 · Published 2026-08-14

Technologies: PAX Technology Q80. Vendors: PAX Technology.

Executive brief

The PAX Technology Q80 is a payment processing device used in retail and hospitality environments. The XCB daemon component lacks proper authentication controls, allowing network-adjacent attackers to access sensitive configuration data and modify device settings without any credentials. Combined with other vulnerabilities, this could enable arbitrary code execution with root privileges, potentially compromising payment card data and device integrity.

Technical details

The vulnerability is an authentication bypass in the XCB daemon of the PAX Q80 payment terminal. The flaw allows unauthenticated network-adjacent attackers to access sensitive functionality and modify device configuration. The attack requires network proximity (AV:A) but no user interaction or privileges. An attacker can disclose sensitive information and modify configuration; in combination with other vulnerabilities, arbitrary code execution as root is possible. The vendor confirmed the issue affects reported firmware versions but indicated end-of-life status; no patch availability has been communicated as of publication.

Affected products

  • PAX Technology Q80 <UNKNOWN>

Timeline

  • 2026-04-22: disclosed: Vulnerability reported to vendor
  • 2026-04-23: other: Vendor confirmed reported firmware was end-of-life
  • 2026-07-21: other: Vendor confirmed issue on reported firmware
  • 2026-08-05: advisory: Coordinated public release (ZDI-26-524)
  • 2026-08-14: other: CVE-2026-19908 published, advisory updated

References

Related threats