PayRange API

Summary

A critical vulnerability (CVE-2026-18965) in PayRange API allows remote attackers to disclose sensitive information, cause denial of service, or alter device images due to missing authorization on management endpoints. Successful exploitation means sensitive data of every device on the PayRange network could be publicly accessible.

IFF Assessment

FOE

The vulnerability allows for unauthorized access and modification of sensitive data and device functionality, posing a significant risk to defenders.

Severity

8.8 High

Defender Context

Defenders should be aware of the missing authorization vulnerability in PayRange API, which could lead to widespread data exposure and service disruption. It is crucial to monitor for any signs of exploitation and to ensure that all systems have appropriate authorization controls in place, especially for management endpoints.

Read Full Story →