SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-67403

CRITICAL · CVSS 9 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-09-09 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

The vulnerability in Cash Collect's Sage AR Automation API allows authenticated users to bypass tenant-level authorization, enabling them to access administrative resources of other tenants by manipulating tenant identifiers. This critical flaw poses a significant risk of unauthorized data exposure and potential administrative control over affected systems. Organizations utilizing this API should prioritize immediate remediation to safeguard sensitive information and maintain tenant isolation.

CVE
CVE-2026-67403
Severity
CRITICAL
CVSS
9
EPSS
0.17%

Original NVD Description

Cash Collect contains an improper authorization vulnerability in the Sage AR Automation API. Insufficient tenant-level authorization checks allow authenticated users to access administrative resources belonging to other tenants by specifying a valid non predictable tenant identifier.