CISA Advisory: PayRange API Missing Authorization Vulnerability (CVE-2026-18965)
CISA released an advisory on August 25, 2026, regarding a vulnerability (CVE-2026-18965) in PayRange API, a product used in commercial facilities. The vulnerability is due to missing authorization on management endpoints, allowing verbose details of every device on the PayRange network to be publicly accessible with or without an account. Successful exploitation could allow a remote, authenticated or unauthenticated attacker to disclose sensitive information, arbitrarily modify the device to cause a denial of service, or alter a device's displayed image. The CVSS base score is 8.8 (High) under CVSS v3.1 and 8.7 (High) under CVSS v4.0. PayRange has not responded to CISA's requests to mitigate the vulnerability. CISA recommends defensive measures such as minimizing network exposure, using firewalls, and isolating control system networks. No known public exploitation has been reported at this time.
What we know
The vulnerability is a missing authorization issue (CWE-862) on management endpoints.
▤ 1 sources›
Exploitation could allow disclosure of sensitive information, device modification, denial of service, or altering displayed images.
▤ 1 sources›
CVSS v3.1 base score is 8.8 (High); CVSS v4.0 base score is 8.7 (High).
▤ 1 sources›
No known public exploitation has been reported to CISA at this time.
▤ 1 sources›
PayRange has not responded to CISA's requests to mitigate the vulnerability.
▤ 1 sources›
CISA published an advisory on 2026-08-25 for CVE-2026-18965 affecting PayRange API.
▤ 1 sources›
CISA published an advisory for a missing authorization vulnerability in PayRange API, which could allow remote attackers to access sensitive device information, modify devices, or cause denial of service. PayRange has not responded to mitigation requests.
Verified · 1 sourcesLive reports
View allComments 0
Discuss this event in persistent threads. Live chat remains separate.
No comments yet. Start the conversation.