CVE-2026-68484: Sage Ar Automation

Critical severity, CVSS 9.0. EPSS: 0.3% chance of exploitation in the next 30 days.

Cash Collect contains an improper authorization vulnerability in the Sage AR Automation API. Administrative functions do not properly verify user privileges, allowing authenticated low-privileged users to create administrator accounts and obtain elevated privileges.

Affected products

  • Sage Sage Ar Automation

Published 2026-09-09. Last modified 2026-09-09.