CVE-2026-68484
Deferred Deferred - Pending Action

Improper Authorization in Cash Collect Sage AR Automation API

Vulnerability report for CVE-2026-68484, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-09

Assigner: HackerOne

Description

Cash Collect contains an improper authorization vulnerability in the Sage AR Automation API. Administrative functions do not properly verify user privileges, allowing authenticated low-privileged users to create administrator accounts and obtain elevated privileges.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-09
Generated
2026-09-30
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
sage ar_automation_api *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Cash Collect has an improper authorization vulnerability in the Sage AR Automation API. This means administrative functions do not check user privileges correctly. Authenticated low-privileged users can exploit this to create administrator accounts and gain elevated access.

Detection Guidance

The provided CVE data does not include specific detection methods or commands for identifying this vulnerability on a network or system. Review Sage AR Automation API logs for unauthorized account creation events or privilege escalation attempts. Check for Magic Link authentication settings being disabled or modified without authorization.

Impact Analysis

An attacker with low privileges could escalate their access to administrator level. This may allow unauthorized changes to system settings, access to sensitive data, or disruption of services. The impact depends on the system's configuration and data stored.

Compliance Impact

This vulnerability could lead to unauthorized access to personal or sensitive data, violating GDPR or HIPAA requirements. Organizations may face compliance violations, legal penalties, and reputational damage if such access occurs.

Mitigation Strategies

Enable default Magic Link secured settings and authentication as recommended in the Sage AR Automation API updates. Ensure administrative functions properly verify user privileges to prevent unauthorized account creation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-68484. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart