ZeroHour

CVE-2026-18965

mass

Missing Authorization in PayRange API Exposes Device Details Fleet-Wide

CVSS 4.0
8.7 high
EPSS
<1%p37
Published
()
Modified
AI analysis

The PayRange API fails to enforce authorization (CWE-862) on its management endpoints, so verbose details for every device connected to the PayRange network are publicly accessible to anyone, whether or not they hold a PayRange account. The flaw is triggered simply by requesting device information from these network-accessible endpoints, with no special privileges or user interaction required. An attacker gains detailed, fleet-wide visibility into PayRange device records, an information-disclosure impact scored 8.7 (High) under CVSS 4.0. Operators whose machines use PayRange payment technology (unattended retail, laundry, and similar deployments) are affected because their device details are exposed. As of this analysis there is no known exploitation, no public proof-of-concept, EPSS is 0.4% (37th percentile), and the issue is not listed in CISA KEV.

What to do: Contact PayRange for patched API/firmware guidance and apply updates as soon as available, since no fixed version is specified in the current data. Monitor for the associated CISA ICS advisory (assigned by [email protected]) for confirmed remediation details, and in the meantime review what device information your fleet's records contain to gauge the sensitivity of the exposure.

Affected
PayRange API (management endpoints)
Estimated exposure
massorder of hundreds of thousands to ~1 million connected devices (estimated; exact count unknown) — The flaw is fleet-wide at the API level, and PayRange's payment-enabled machine fleet (vending, laundry, amusement and similar unattended retail) has been publicly reported at roughly one million deployed units, so the plausibly affected…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

PayRange API is missing proper authorization on management endpoints, which allows verbose details of every device on the PayRange network to be publicly accessible, with or without an account.

Weakness
CWE-862
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.