PT-2026-82269 · Payrange · Payrange Api

·

CVE-2026-18965

·

Published

2026-08-26

·

Updated

2026-08-28

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PayRange API (affected versions not specified)
Description The PayRange API lacks proper authorization on management endpoints, allowing public access to verbose details of every device on the network, regardless of whether the requester has an account. This issue was exploited to bypass authorization and gain unrestricted access to device details across the payment network, facilitating reconnaissance of network topology and potential lateral movement to payment terminals.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. Implement runtime segmentation to limit the potential blast radius of an expansion.

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-18965

Affected Products

Payrange Api