Improper Authorization Vulnerability in Sage AR Automation API
CVE-2026-68484
9CRITICAL
What is CVE-2026-68484?
The Cash Collect system is affected by an improper authorization vulnerability in the Sage AR Automation API. This flaw allows authenticated users with low privileges to bypass proper verification measures, enabling them to create new administrator accounts and gain elevated privileges. As a result, this vulnerability creates opportunities for unauthorized access, potentially compromising sensitive administrative functions and data integrity.
Affected Version(s)
Sage AR Automation June-R1-2026
