CVE-2026-67403

Cash Collect contains an improper authorization vulnerability in the Sage AR Automation API. Insufficient tenant-level authorization checks allow authenticated users to access administrative resources belonging to other tenants by specifying a valid non predictable tenant identifier.

  • Published Sep 9, 2026
  • CVSS 9.0 critical
  • 0.3% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-67403 at the National Vulnerability Database