Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Tahi Wilton Geary

#31125of 56,335
8.8Total CVSS
Vulnerabilities · 1
PT-2026-82269
8.8
2026-08-26
Payrange · Payrange Api · CVE-2026-18965
**Name of the Vulnerable Software and Affected Versions** PayRange API (affected versions not specified) **Description** The PayRange API lacks proper authorization on management endpoints, allowing public access to verbose details of every device on the network, regardless of whether the requester has an account. This issue was exploited to bypass authorization and gain unrestricted access to device details across the payment network, facilitating reconnaissance of network topology and potential lateral movement to payment terminals. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability. Implement runtime segmentation to limit the potential blast radius of an expansion.