{"id":"CVE-2026-68484","title":"Cash Collect contains an improper authorization vulnerability in the Sage AR Automation API","summary":"Cash Collect contains an improper authorization vulnerability in the Sage AR Automation API. Administrative functions do not properly verify user privileges, allowing authenticated low-privileged users to create administrator accounts an…","severity":"critical","cvss":9,"cvssVector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H","cwe":["CWE-862"],"vendor":"Sage","product":"Sage AR Automation","affected":["ar_automation >= June-R1-2026 < June-R1-2026"],"published":"2026-09-09","updated":"2026-09-09","sourceUpdated":"2026-09-09T20:20:21.673","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-68484","references":[{"url":"https://helpcenter.sara.sage.com/hc/en-us/articles/52106283946651-June-R2-Release-2026","label":"support@hackerone.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-09T19:01:12.375422Z"},"cvssSource":"cna","ingestedAt":"2026-09-09T16:14:05.562Z","epss":0.0017,"epssPercentile":0.0672,"slug":"CVE-2026-68484","body":"## Overview\n\nCash Collect contains an improper authorization vulnerability in the Sage AR Automation API. Administrative functions do not properly verify user privileges, allowing authenticated low-privileged users to create administrator accounts and obtain elevated privileges.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":50,"depthScoreParts":{"impact":49.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}