Impact
The vulnerability, identified as an improper authorization flaw in the Cash Collect component of Sage AR Automation, allows an authenticated user to manipulate tenant identifiers in API requests. By supplying a valid, non‑predictable tenant ID that does not belong to the user’s own tenant, the attacker can access administrative resources of other tenants. This flaw can lead to disclosure, alteration, or denial of critical business data belonging to those tenants.
Affected Systems
The affected product is Sage AR Automation from Sage. No specific version range is provided, but the issue is reported against the release available in the June R2 Release 2026.
Risk and Exploitability
The CVSS base score of 9.0 indicates a critical severity. EPSS information is not available, and the vulnerability has not yet appeared in the CISA KEV catalog. The attack can be carried out by an authenticated user that understands how to construct the tenant identifier; the process is inferred to be straightforward and requires no special privileges beyond API access.
OpenCVE Enrichment