Description
Cash Collect contains an improper authorization vulnerability in the Sage AR Automation API. Insufficient tenant-level authorization checks allow authenticated users to access administrative resources belonging to other tenants by specifying a valid non predictable tenant identifier.
Published: 2026-09-09
Score: 9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Cross‑Tenant Administrative Access
Action: Apply Patch
AI Analysis

Impact

The vulnerability, identified as an improper authorization flaw in the Cash Collect component of Sage AR Automation, allows an authenticated user to manipulate tenant identifiers in API requests. By supplying a valid, non‑predictable tenant ID that does not belong to the user’s own tenant, the attacker can access administrative resources of other tenants. This flaw can lead to disclosure, alteration, or denial of critical business data belonging to those tenants.

Affected Systems

The affected product is Sage AR Automation from Sage. No specific version range is provided, but the issue is reported against the release available in the June R2 Release 2026.

Risk and Exploitability

The CVSS base score of 9.0 indicates a critical severity. EPSS information is not available, and the vulnerability has not yet appeared in the CISA KEV catalog. The attack can be carried out by an authenticated user that understands how to construct the tenant identifier; the process is inferred to be straightforward and requires no special privileges beyond API access.

Generated by OpenCVE AI on September 9, 2026 at 18:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Sage AR Automation to the June R2 Release 2026, which contains the authorisation fix.
  • Verify that tenant‑level authorization checks are enforced by testing the API with cross‑tenant tenant IDs; ensure that requests are rejected when the tenant does not belong to the authenticated user.
  • Implement continuous monitoring of API traffic for anomalous tenant‑ID usage and restrict roles that can execute administrative API calls to the minimum required set of operators.

Generated by OpenCVE AI on September 9, 2026 at 18:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Sage
Sage sage Ar Automation
Vendors & Products Sage
Sage sage Ar Automation

Wed, 09 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Title Improper Authorization in Sage AR Automation API Enables Cross‑Tenant Administrative Access

Wed, 09 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description Cash Collect contains an improper authorization vulnerability in the Sage AR Automation API. Insufficient tenant-level authorization checks allow authenticated users to access administrative resources belonging to other tenants by specifying a valid non predictable tenant identifier.
Weaknesses CWE-639
References
Metrics cvssV4_0

{'score': 9, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

Sage Sage Ar Automation
cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2026-09-09T19:07:40.225Z

Reserved: 2026-07-29T15:00:02.294Z

Link: CVE-2026-67403

cve-icon Vulnrichment

Updated: 2026-09-09T19:07:21.888Z

cve-icon NVD

Status : Deferred

Published: 2026-09-09T16:17:04.030

Modified: 2026-09-09T20:20:21.673

Link: CVE-2026-67403

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T20:10:07Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key