What is CVE-2026-19908?
A missing authentication vulnerability exists in the XCB Daemon of PAX Technology Q80 payment terminals. This flaw allows network-adjacent attackers to disclose sensitive information and modify device configurations without any authentication. Network-level isolation is recommended until an official patch is released by PAX Technology.
Azərbaycanca: PAX Technology Q80 ödəmə terminalında XCB Daemon xidmətində autentifikasiya çatışmazlığı aşkar edilib. Bu boşluq şəbəkə üzərindən yaxınlıqdakı təcavüzkarlara autentifikasiya olmadan həssas məlumatları əldə etməyə və cihaz konfiqurasiyasını dəyişməyə imkan verir. PAX Technology tərəfindən rəsmi yamaq və ya təhlükəsizlik yeniləməsi tətbiq olunana qədər cihazların şəbəkə səviyyəsində izolyasiyası tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-306
FAQ1
What does the XCB Daemon vulnerability in PAX Technology Q80 terminals allow an attacker to do?
The CVE-2026-19908 vulnerability allows network-adjacent attackers to disclose sensitive information and modify device configurations without any authentication.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.