Executive brief
Cash Collect is a Sage accounts receivable automation platform used to manage customer payments and collections. A flaw in the API's authorization checks allows authenticated users to bypass tenant isolation and access administrative data and functions belonging to other organizations, potentially exposing sensitive financial information and enabling unauthorized account manipulation.
Technical details
The vulnerability is an improper authorization flaw in the Sage AR Automation API where tenant-level access controls are insufficiently enforced. Authenticated users can specify a non-predictable but valid tenant identifier to access administrative resources and data belonging to other tenants, effectively bypassing tenant isolation. The attack requires valid authentication credentials but no additional user interaction or elevated privileges. An attacker can enumerate or brute-force tenant identifiers to gain unauthorized access to other organizations' financial records and administrative functions. Patch availability has not been confirmed in the provided advisory information.
Affected products
- Sage Cash Collect <UNKNOWN>
Timeline
- 2026-09-09: disclosed