AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-19908

HIGH · CVSS 7.1 Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-14 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The PAX Technology Q80 XCB Daemon is vulnerable due to a lack of authentication, enabling network-adjacent attackers to access sensitive information and modify configurations without any prior authentication. This flaw can be exploited in conjunction with other vulnerabilities to execute arbitrary code with root privileges. Organizations using PAX Technology Q80 should prioritize addressing this vulnerability to mitigate the risk of unauthorized access and potential system compromise.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-19908
Severity
HIGH
CVSS
7.1
EPSS
N/A

Original NVD Description

PAX Technology Q80 XCB Daemon Missing Authentication Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information and modify configuration on affected installations of PAX Technology Q80. Authentication is not required to exploit this vulnerability. The specific flaw exists within the XCB daemon. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of root. Was ZDI-CAN-30584.