VU#360868: Analog Way Pictural... Note

VU#360868: Analog Way Picturall Quad Compact Mark II contains a local privilege escalation vulnerability

Analog Way's Picturall Quad Compact Mark II server, version 3.5.8, has a critical vulnerability. This local privilege escalation flaw is tracked as CVE-2026-14985. The vulnerability stems from flaws in a maintenance script named create_local_installer.sh. Specifically, improper privilege delegation and insufficient input validation are the root causes. The default permissions allow a low-privileged user to execute create_local_installer.sh as root without a password. An attacker can craft a malicious disk image containing a specially formatted file. This file, picturall-version.txt, uses directory traversal strings to trick the script. The script fails to properly sanitize input from this attacker-supplied file. Consequently, an attacker can write files to any location on the system. This allows arbitrary file writes to sensitive directories like /etc/cron.d. Ultimately, this enables the execution of arbitrary code with full root privileges. Analog Way has released version 3.5.9 to fix this security issue. Users should update immediately to protect their systems.