ar_automation vulnerabilities
CVEs whose affected-version data names the ar_automation package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-68484Critical· 9.0Cash Collect contains an improper authorization vulnerability in the Sage AR Automation API
Cash Collect contains an improper authorization vulnerability in the Sage AR Automation API. Administrative functions do not properly verify user privileges, allowing authenticated low-privileged users to create administrator accounts an…
▾ MidnightSage · Sage AR AutomationEPSS 0.17%via NVD
CVE-2026-67403Critical· 9.0Cash Collect contains an improper authorization vulnerability in the Sage AR Automation API
Cash Collect contains an improper authorization vulnerability in the Sage AR Automation API. Insufficient tenant-level authorization checks allow authenticated users to access administrative resources belonging to other tenants by specif…
▾ MidnightSage · Sage AR AutomationEPSS 0.17%via NVD