Project Subscriptions
No data.
No advisories yet.
Solution
PayRange has not responded to requests to work with CISA to mitigate this vulnerability. Users of PayRange devices are invited to contact PayRange customer support at support@payrange.com for additional information.
Workaround
No workaround given by the vendor.
Fri, 28 Aug 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 27 Aug 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PayRange API is missing proper authorization on management endpoints, which allows verbose details of every device on the PayRange network to be publicly accessible, with or without an account. | |
| Title | Missing Authorization in PayRange API | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-08-28T15:57:53.992Z
Reserved: 2026-08-05T15:10:48.838Z
Link: CVE-2026-18965
Updated: 2026-08-28T15:45:45.617Z
Status : Received
Published: 2026-08-28T00:16:48.933
Modified: 2026-08-28T20:17:23.560
Link: CVE-2026-18965
No data.
OpenCVE Enrichment
Updated: 2026-08-28T05:45:04Z