Security & Threat Intelligence · 25.08.2026, 19:47 UTC
PayRange API
| Schweregrad | info |
|---|---|
| CVE | ↗ |
| Kategorie | Security & Threat Intelligence |
| Quelle | CISA Advisories ↗ |
| Veröffentlicht | 25.08.2026 UTC |
Sicherheitsmeldung mit Schweregrad noch nicht bewertet. Betroffene Kennungen: CVE-2026-18965. Technische Details im Tab „Originaltext“; empfohlene Schritte in der Checkliste.
View CSAF Summary Successful exploitation of this vulnerability could allow a remote, authenticated or unauthenticated attacker to disclose sensitive information, arbitrarily modify the device to cause a denial of service, or alter a devices displayed image. The following versions of PayRange API are affected:
PayRange API vers:all/*
CVSS Vendor Equipment Vulnerabilities
v3 8.8 PayRange PayRange API Missing Authorization
Background
Critical Infrastructure Sectors: Commercial Facilities Countries/Areas Deployed: United States, Canada Company Headquarters Location: United States
Vulnerabilities
Expand All +
CVE-2026-18965
The affected product is missing proper authorization on management endpoints, which allows verbose details of every device on the PayRange network to be publicly accessible, with or without an account. View CVE Details
Affected Products PayRange API
Vendor:PayRange Product Version:PayRange PayRange API: vers:all/* Product Status:known_affected
Remediations MitigationPayRange has not responded to requests to work with CISA to mitigate this vulnerability. Users of PayRange devices are invited to contact PayRange customer support at support@payrange.com for additional information.mailto:support@payrange.com
Relevant CWE: CWE-862 Missing Authorization
Metrics
CVSS Version Base Score Base Severity Vector String
3.1 8.8 HIGH CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
4.0 8.7 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Acknowledgments
Tahi Wilton Geary reported this vulnerability to CISA
Legal Notice and Terms of …