CVE-2026-18965: Missing Authorization in PayRange API
Published Aug 27, 2026
·Updated
PayRange API is missing proper authorization on management endpoints, which allows verbose details of every device on the PayRange network to be publicly accessible, with or without an account.
Affected Software
1 affected component
PayRange API
Event History
Aug 27, 2026
CVE Published
via MITRE·08:34 PM
Data Sourced
via MITRE·08:34 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Which environments may expose information through this issue?
PayRange networks may be exposed because the affected management endpoints can make verbose details for every device on the PayRange network publicly accessible.
2
Does an attacker need a PayRange account to access the exposed device information?
No. The vulnerability description states that the information may be accessible with or without an account.