CVE-2026-68484 Details
Description
Cash Collect contains an improper authorization vulnerability in the Sage AR Automation API. Administrative functions do not properly verify user privileges, allowing authenticated low-privileged users to create administrator accounts and obtain elevated privileges.
A vulnerability allowing improper authorization has been identified in the Sage Cash Collect application, specifically within the Accounts Receivable (AR) Automation API. This issue arises because administrative functions fail to adequately verify user privileges. As a result, authenticated users with low privileges can create administrator accounts and gain elevated rights.
Users are advised to refer to the Sage Help Center for guidance on securing Magic Link authentication, which can enhance login security.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 9, 2026CISA-ADP
Assessed Sep 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://helpcenter.sara.sage.com/hc/en-us/articles/52106283946651-June-R2-Release-2026 | [email protected] | Release NotesVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Sage Cash Collect | All versions |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 9, 2026 | CVE Modified | CISA-ADP |
| Sep 9, 2026 | New CVE Received | [email protected] |
Volerion