CVE-2026-68484: Sage AR Automation API vulnerability
Published Sep 9, 2026
·Updated
Cash Collect contains an improper authorization vulnerability in the Sage AR Automation API. Administrative functions do not properly verify user privileges, allowing authenticated low-privileged users to create administrator accounts and obtain elevated privileges.
Affected Software
1 affected component
Sage AR Automation API
Event History
Sep 9, 2026
CVE Published
via MITRE·03:49 PM
Data Sourced
via MITRE·03:49 PM
DescriptionWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An authenticated low-privileged user of the Sage AR Automation API can exploit the affected administrative functions. The issue does not require an existing administrator account.
2
What level of access can an attacker gain?
A successful attacker can create administrator accounts and elevate their privileges to administrative access.