ZeroHour

CVE-2026-67403

Tenant Authorization Bypass (IDOR) in Cash Collect Sage AR Automation API

CVSS 4.0
9.0 critical
EPSS
<1%p7
Published
()
Modified
AI analysis

Cash Collect's Sage AR Automation API contains an improper authorization flaw (CWE-639) in which tenant-level permission checks are not enforced when a tenant identifier is supplied. An authenticated, low-privileged user can pass a valid but otherwise non-predictable tenant identifier belonging to another tenant, and the API serves that tenant's administrative resources without verifying ownership; the high attack complexity in the CVSS 4.0 score reflects the need to know or obtain a valid tenant ID. Successful exploitation provides network-based, cross-tenant access to administrative resources with no user interaction or additional privileges, with high impact on the confidentiality, integrity, and availability of other tenants' data. Any organization running Cash Collect with the Sage AR Automation API enabled is potentially exposed, since the flaw is in multi-tenant access control rather than a specific code path; affected and fixed version ranges are not provided in the available data. There is currently no public proof-of-concept, the issue is not in CISA's KEV, and no in-the-wild exploitation is known.

What to do: Contact the vendor for a patched build and upgrade as soon as one is identified, since no fixed version is specified in the available data. In the meantime, audit Sage AR Automation API access logs for authenticated requests referencing tenant identifiers other than the caller's own (evidence of cross-tenant access), and restrict API access to the minimum necessary accounts while monitoring for anomalous tenant-ID usage.

Affected
Cash Collect (Sage AR Automation API)
Estimated exposure
unknown; plausibly hundreds to low thousands of tenant organizations given it is a niche B2B accounts-receivable automation integration, but no public… — No public active-install counts, internet-exposed scan data, or market-share figures are available for Cash Collect, so the affected population cannot be quantified; the product appears to be a niche B2B AR-automation add-on for Sage users…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Cash Collect contains an improper authorization vulnerability in the Sage AR Automation API. Insufficient tenant-level authorization checks allow authenticated users to access administrative resources belonging to other tenants by specifying a valid non predictable tenant identifier.

Weakness
CWE-639
Vector
CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.