CVE-2026-18965

High8.8Published on August 27, 2026

PayRange API is missing proper authorization on management endpoints, which allows verbose details of every device on the PayRange network to be publicly accessible, with or without an account.

CVSS score8.8 / 10CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness type (CWE)CWE-862

Related articles

This product uses the NVD API but is not endorsed or certified by the NVD.

CVE database