Signature Verification Bypass in PAX Technology Q80 Application Installer
CVE-2026-19910

7.5HIGH

Key Information:

Status
Vendor
CVE Published:
14 August 2026

What is CVE-2026-19910?

A vulnerability in the application installer of PAX Technology Q80 allows attackers on the same network to exploit a flaw in cryptographic signature verification. This oversight permits arbitrary code execution without requiring authentication, facilitating more extensive attacks that can compromise the system at the root level. By leveraging this vulnerability, attackers may combine it with other weaknesses to enhance their access, making proactive measures essential for safeguarding affected installations.

Affected Version(s)

Q80 2.6.33.6690R

References

CVSS V3.0

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.