Improper Authorization Vulnerability in Sage AR Automation API
CVE-2026-68484

9CRITICAL

Key Information:

Vendor

Sage

Vendor
CVE Published:
9 September 2026

What is CVE-2026-68484?

The Cash Collect system is affected by an improper authorization vulnerability in the Sage AR Automation API. This flaw allows authenticated users with low privileges to bypass proper verification measures, enabling them to create new administrator accounts and gain elevated privileges. As a result, this vulnerability creates opportunities for unauthorized access, potentially compromising sensitive administrative functions and data integrity.

Affected Version(s)

Sage AR Automation June-R1-2026

References

CVSS V4

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jess Parker - California Lottery
.