Junglewise Threat Intelligence

CVE-2026-19910: PAX Technology Q80 Application Installer signature verification bypass

CVE-2026-19910 · Severity: high · CVSS 7.5 · Published 2026-08-14

Technologies: PAX Technology Q80. Vendors: PAX Technology.

Executive brief

PAX Technology Q80 is a point-of-sale terminal widely used in retail and hospitality environments. This vulnerability allows a network-adjacent attacker to install malicious applications on the device without valid authorization, executing code with root privileges. An attacker could compromise payment processing, steal customer data, or disrupt business operations.

Technical details

The vulnerability is a cryptographic signature verification bypass in the application installer component of PAX Q80. The installer fails to properly validate the signature of application packages before installation, allowing an attacker to install unsigned or maliciously-signed applications. Attack requires network adjacency but no authentication. An attacker can leverage this flaw in conjunction with other vulnerabilities to achieve remote code execution in the root context. The vendor has declared the affected firmware end-of-life and no longer supported; however, ZDI reports that users cannot upgrade to patched versions.

Affected products

  • PAX Technology Q80 end-of-life firmware

Timeline

  • 2026-04-22: disclosed: Vulnerability reported to PAX Technology
  • 2026-04-23: other: Vendor confirmed affected firmware is end-of-life
  • 2026-07-21: other: Vendor confirmed issue on reported firmware
  • 2026-08-14: advisory: Coordinated public release (ZDI-26-526, CVE-2026-19910)

References

Related threats