๐Ÿ” CVE Alert

CVE-2026-67403

UNKNOWN 0.0
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Cash Collect contains an improper authorization vulnerability in the Sage AR Automation API. Insufficient tenant-level authorization checks allow authenticated users to access administrative resources belonging to other tenants by specifying a valid non predictable tenant identifier.

CWE CWE-639
Vendor sage
Product sage ar automation
Published Sep 9, 2026
Last Updated Sep 9, 2026
Stay Ahead of the Next One

Get instant alerts for sage sage ar automation

Be the first to know when new unknown vulnerabilities affecting sage sage ar automation are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Sage / Sage AR Automation
June-R1-2026 < June-R1-2026

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
helpcenter.sara.sage.com: https://helpcenter.sara.sage.com/hc/en-us/articles/52106283946651-June-R2-Release-2026

Credits

๐Ÿ” Jess Parker - California Lottery