CVE-2026-18965
8.8
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Summary
PayRange API is missing proper authorization on management endpoints, which allows verbose details of every device on the PayRange network to be publicly accessible, with or without an account.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| PayRange | PayRange API | All versions | affected |
Weaknesses
- CWE-862: CWE-862 Missing Authorization
References
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-04
- https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-237-04.json
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.