CVE-2026-18965
8.8PayRange · PayRange API
The PayRange API lacks proper authorization on management endpoints, allowing unauthorized access to sensitive device details, configuration modifications, and potential denial of service.
Executive summary
A critical authorization vulnerability in the PayRange API allows remote, unauthenticated attackers to access sensitive device information and disrupt service.
Vulnerability
This is a missing authorization flaw (CWE-862) affecting management endpoints. The vulnerability allows any remote user, regardless of authentication status, to access, modify, or disrupt devices connected to the PayRange network.
Business impact
With a CVSS score of 8.8, this vulnerability poses a severe risk to operational integrity. Successful exploitation could lead to total loss of device control, unauthorized disclosure of proprietary network data, and significant service outages. Organizations relying on PayRange hardware face potential reputational damage and operational downtime if these management endpoints remain exposed.
Remediation
Immediate Action: As no patch is currently available, immediately restrict network access to management endpoints to authorized personnel only using firewall rules or network segmentation.
Proactive Monitoring: Review access logs for unusual traffic patterns targeting management APIs and monitor devices for unexpected configuration changes or service interruptions.
Compensating Controls: Deploy a Web Application Firewall (WAF) or API gateway to enforce strict access control policies and block requests to sensitive endpoints from unauthorized sources.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the lack of a vendor-provided patch, stakeholders must prioritize network-level isolation of all PayRange API endpoints. Security teams should treat this as a high-priority exposure and ensure that internal network segments are hardened against unauthorized access to these management interfaces until a formal resolution is released.
Sources
Originally found and disclosed by Tahi Wilton Geary reported this vulnerability to CISA., per the CVE Program record.