PayRange API is missing proper authorization on management endpoints, which allows verbose details of every device on the PayRange network to be publicly accessible, with or without an account.
Metrics
Affected Vendors & Products
References
History
Tue, 01 Sep 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Payrange
Payrange payrange |
|
| Vendors & Products |
Payrange
Payrange payrange |
Fri, 28 Aug 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 27 Aug 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PayRange API is missing proper authorization on management endpoints, which allows verbose details of every device on the PayRange network to be publicly accessible, with or without an account. | |
| Title | Missing Authorization in PayRange API | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: icscert
Published: 2026-08-27T20:34:16.692Z
Updated: 2026-08-28T15:57:53.992Z
Reserved: 2026-08-05T15:10:48.838Z
Link: CVE-2026-18965
Updated: 2026-08-28T15:45:45.617Z
Status : Deferred
Published: 2026-08-28T00:16:48.933
Modified: 2026-08-31T19:18:40.503
Link: CVE-2026-18965
No data.