ZeroHour

CVE-2026-68484

Improper Authorization in Cash Collect (Sage AR Automation API) Grants Admin Access

CVSS 4.0
9.0 critical
EPSS
<1%p7
Published
()
Modified
AI analysis

Cash Collect contains an improper authorization flaw (CWE-862) in its Sage AR Automation API, where administrative functions fail to verify the caller's user privileges. An authenticated low-privileged user can invoke these administrative functions over the network and, because permission checks are missing, create new administrator accounts. By creating an admin account, the attacker elevates their privileges to full administrative control, consistent with the critical CVSS 4.0 score of 9 and high impact across confidentiality, integrity, and availability. Any organization running Cash Collect with the Sage AR Automation API and low-privileged user accounts is exposed, though the specific affected version range is not stated in the available disclosure data. Exploitation is not known in the wild: the issue is not in CISA's KEV catalog and no public proof-of-concept is available.

What to do: Contact the Cash Collect vendor to identify the fixed release and upgrade promptly, as no patched version numbers are included in the available data. In the interim, restrict access to the Sage AR Automation API, audit existing user accounts for recently created or unauthorized administrators, and limit how many low-privileged accounts can reach the API.

Affected
Cash Collect — Sage AR Automation API administrative functions
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Cash Collect contains an improper authorization vulnerability in the Sage AR Automation API. Administrative functions do not properly verify user privileges, allowing authenticated low-privileged users to create administrator accounts and obtain elevated privileges.

Weakness
CWE-862
Vector
CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.