Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 0.2%top 93%

CVE-2026-14985: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Analog Way Picturall Quad Compact Mark II

0
High
VulnerabilityCVE-2026-14985cvecve-2026-14985cwe-22cwe-250linuxlocal
Published: 07/22/2026 (07/22/2026, 14:32:31 UTC)
Source: CVE Database V5
Vendor/Project: Analog Way
Product: Picturall Quad Compact Mark II

Description

Overview Version 3.5.8 of Analog Way's Picturall Quad Compact Mark II server contains a local privilege escalation vulnerability, tracked as CVE-2026-14985, due to improper privilege delegation and insufficient input validation in a maintenance script. Description The Picturall Quad Compact Mark II is a compact, heavy-duty 8K media server developed by Analog Way for video playback and content management in professional audiovisual environments. The core firmware includes a maintenance script called create_local_installer.sh , and the default script permission allows the low-privileged user, picmedia , to execute it as root and without a password. An attacker creates a malicious Ext4 disk image that contains the file, picturall-version.txt , with a directory traversal string and a payload file. create_local_installer.sh reads input from picturall-version.txt when processing these attacker-supplied disk images. This input is not properly sanitized, allowing an attacker to supply directory traversal sequences. As a result, the attacker can manipulate the script to write files outside of the intended extraction directory and execute a malicious payload. Because the script executes with root privileges, this behavior enables arbitrary file writes to sensitive system locations such as `/etc/cron.d, a system directory in Unix/Linux operating system used to store system-wide task scheduling files. An attacker can then leverage this capability to execute arbitrary code with root privileges. Impact By exploiting this path traversal vulnerability, an attacker with local access to the device can write arbitrary files to privileged locations. This access allows modification of scheduled tasks, and system configuration files. It can also allow the execution of a[RM2.1][MB2.2]rbitrary commands with full system privileges. An attacker does not need valid root credentials to enable straightforward and repeatable exploitation, resulting in complete system compromise.[RM3.1][MB3.2] This constitutes a Technical Impact = Total under the SSVC framework, meaning: The vulnerability gives the adversary total control over the behavior of the software or total disclosure of all information on the affected system. Solution Analog Way has released version 3.5.9 to address this vulnerability. Users are strongly encouraged to update to the fixed release as soon as possible. Acknowledgements Thanks to the reporter James Tully for responsibly disclosing this issue. This document was written by Michael Bragg. Vendor Information One or more vendors are listed for this advisory. Please reference the full report for more information. Other Information CVE IDs: CVE-2026-14985 Date Public: 2026-07-22 Date First Published: 2026-07-22 Date Last Updated: 2026-07-22 14:30 UTC Document Revision: 1 About vulnerability notes Contact us about this vulnerability Provide a vendor statement

CVSS v3.1

Score 7.8high

Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected software

Affected versions
3.5.8

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/30/2026, 01:09:15 UTC

Technical Analysis

CVE-2026-14985 is a local privilege escalation vulnerability in Analog Way Picturall Quad Compact Mark II version 3.5.8. The core firmware includes a maintenance script that improperly delegates privileges and fails to adequately validate input, leading to a path traversal vulnerability (CWE-22) and improper limitation of pathname to a restricted directory (CWE-250). This allows an attacker with local access and some privileges to escalate their privileges to a higher level, potentially gaining full control over the device.

Potential Impact

Successful exploitation of this vulnerability can lead to full compromise of the device by escalating local privileges. Confidentiality, integrity, and availability of the system are all impacted as indicated by the CVSS vector (C:H/I:H/A:H). This could allow attackers to execute unauthorized commands or modify system configurations.

Mitigation Recommendations

Patch status is not yet confirmed — check the vendor advisory at https://www.kb.cert.org/vuls/id/360868 for current remediation guidance. No official fix or temporary workaround has been publicly documented at this time. Users should monitor the vendor advisory for updates and apply any patches or mitigations once available.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
certcc
Date Reserved
2026-07-07T18:00:27.130Z
Cvss Version
null
State
PUBLISHED
Remediation Level
null
Vendor Advisory Urls
[{"url":"https://www.kb.cert.org/vuls/id/360868","vendor":"CERT"}]

Threat ID: 6a60d93c9c2644c7f8363a16

Added to database: 07/22/2026, 14:52:44 UTC

Last enriched: 07/30/2026, 01:09:15 UTC

Last updated: 09/04/2026, 10:52:07 UTC

Views: 78

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses