Junglewise Threat Intelligence

CVE-2026-68484: Sage Cash Collect privilege escalation in AR Automation API

CVE-2026-68484 · Severity: info · CVSS 7.1 · Published 2026-09-09

Executive brief

Sage Cash Collect, a financial automation tool for accounts receivable, contains an authorization flaw in its AR Automation API that allows low-level employees to create administrator accounts and gain full system access. An authenticated user with minimal permissions can exploit this vulnerability to elevate their privileges, potentially enabling account creation, data manipulation, or unauthorized financial transactions.

Technical details

The vulnerability is an improper authorization flaw in the Sage AR Automation API where administrative functions fail to properly verify user privilege levels. Exploitation requires valid authentication (network-accessible API endpoint), allowing an authenticated low-privileged user to invoke administrative operations—specifically account creation—without corresponding authorization checks. An attacker with any valid user account can escalate to full administrator rights, bypassing role-based access controls. Patch availability is not mentioned in the advisory.

Affected products

  • Sage Cash Collect <UNKNOWN>

Timeline

  • 2026-09-09: disclosed

References

Related threats