CVE-2026-67403

Summary

Cash Collect contains an improper authorization vulnerability in the Sage AR Automation API. Insufficient tenant-level authorization checks allow authenticated users to access administrative resources belonging to other tenants by specifying a valid non predictable tenant identifier.

Affected Software

VendorProductVersion RangeStatus
SageSage AR AutomationJune-R1-2026 < June-R1-2026affected

Weaknesses

  • CWE-639: CWE-639 Insecure Direct Object Reference (IDOR)

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References