Description
Cash Collect contains an improper authorization vulnerability in the Sage AR Automation API. Administrative functions do not properly verify user privileges, allowing authenticated low-privileged users to create administrator accounts and obtain elevated privileges.
Published: 2026-09-09
Score: 9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Patch ASAP
AI Analysis

Impact

The vulnerability is an improper authorization flaw in the Sage AR Automation API. Authenticated users with low privileges can create new administrator accounts, thereby obtaining elevated rights. This flaw allows a user to bypass normal permission checks and elevate privileges, presenting a serious threat to the integrity and confidentiality of the system.

Affected Systems

The affected product is Sage AR Automation. No specific version numbers are listed, but the issue is tracked under Sage’s June R2 2026 release notes.

Risk and Exploitability

The CVSS score of 9.0 indicates a critical severity. EPSS data is not available, so the probability of exploitation is unknown, and the vulnerability is not currently listed in the CISA KEV catalog. Attackers need only be authenticated with a low‑privilege account to exploit the flaw, making it easily reachable in environments where API access is granted to non‑administrative users.

Generated by OpenCVE AI on September 9, 2026 at 18:29 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Sage AR Automation update that fixes the authorization flaw once it becomes available.
  • Restrict API access to only privileged users and enforce strict role‑based checks to prevent creation of administrator accounts by low‑privileged users.
  • Continuously monitor account creation logs for anomalous administrator account creation and investigate any unexpected changes.

Generated by OpenCVE AI on September 9, 2026 at 18:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Sage
Sage sage Ar Automation
Vendors & Products Sage
Sage sage Ar Automation

Wed, 09 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Title Improper Authorization in Sage AR Automation Allows Low‑Privileged Users to Create Admin Accounts

Wed, 09 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description Cash Collect contains an improper authorization vulnerability in the Sage AR Automation API. Administrative functions do not properly verify user privileges, allowing authenticated low-privileged users to create administrator accounts and obtain elevated privileges.
Weaknesses CWE-862
References
Metrics cvssV4_0

{'score': 9, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

Sage Sage Ar Automation
cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2026-09-09T19:03:29.974Z

Reserved: 2026-07-30T15:00:00.608Z

Link: CVE-2026-68484

cve-icon Vulnrichment

Updated: 2026-09-09T19:02:07.110Z

cve-icon NVD

Status : Deferred

Published: 2026-09-09T16:17:04.157

Modified: 2026-09-09T20:20:21.673

Link: CVE-2026-68484

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T20:10:05Z

Weaknesses