Impact
The vulnerability is an improper authorization flaw in the Sage AR Automation API. Authenticated users with low privileges can create new administrator accounts, thereby obtaining elevated rights. This flaw allows a user to bypass normal permission checks and elevate privileges, presenting a serious threat to the integrity and confidentiality of the system.
Affected Systems
The affected product is Sage AR Automation. No specific version numbers are listed, but the issue is tracked under Sage’s June R2 2026 release notes.
Risk and Exploitability
The CVSS score of 9.0 indicates a critical severity. EPSS data is not available, so the probability of exploitation is unknown, and the vulnerability is not currently listed in the CISA KEV catalog. Attackers need only be authenticated with a low‑privilege account to exploit the flaw, making it easily reachable in environments where API access is granted to non‑administrative users.
OpenCVE Enrichment