CVE-2026-67403
Tenant Authorization Bypass (IDOR) in Cash Collect Sage AR Automation API
Cash Collect's Sage AR Automation API contains an improper authorization flaw (CWE-639) in which tenant-level permission checks are not enforced when a tenant identifier is supplied. An authenticated, low-privileged user can pass a valid but otherwise non-predictable tenant identifier belonging to another tenant, and the API serves that tenant's administrative resources without verifying ownership; the high attack complexity in the CVSS 4.0 score reflects the need to know or obtain a valid tenant ID. Successful exploitation provides network-based, cross-tenant access to administrative resources with no user interaction or additional privileges, with high impact on the confidentiality, integrity, and availability of other tenants' data. Any organization running Cash Collect with the Sage AR Automation API enabled is potentially exposed, since the flaw is in multi-tenant access control rather than a specific code path; affected and fixed version ranges are not provided in the available data. There is currently no public proof-of-concept, the issue is not in CISA's KEV, and no in-the-wild exploitation is known.
What to do: Contact the vendor for a patched build and upgrade as soon as one is identified, since no fixed version is specified in the available data. In the meantime, audit Sage AR Automation API access logs for authenticated requests referencing tenant identifiers other than the caller's own (evidence of cross-tenant access), and restrict API access to the minimum necessary accounts while monitoring for anomalous tenant-ID usage.
| Cash Collect (Sage AR Automation API) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Cash Collect contains an improper authorization vulnerability in the Sage AR Automation API. Insufficient tenant-level authorization checks allow authenticated users to access administrative resources belonging to other tenants by specifying a valid non predictable tenant identifier.
- Weakness
- CWE-639
- Vector
- CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.