VYPR
advisoryPublished Aug 25, 2026· 1 source

CISA Warns of Critical Missing Authorization Flaw in PayRange API

CISA has issued an advisory for CVE-2026-18965 affecting PayRange API, a vulnerability that could allow remote attackers to disclose sensitive information or cause denial of service.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has released an advisory detailing a critical vulnerability, identified as CVE-2026-18965, within the PayRange API. This flaw impacts all versions of the PayRange API and stems from a fundamental issue of missing authorization on key management endpoints.

The vulnerability allows remote attackers, who may or may not require authentication, to exploit the misconfiguration. Successful exploitation could lead to significant security breaches, including the disclosure of sensitive information related to every device on the PayRange network. Furthermore, attackers could potentially alter device configurations, leading to denial-of-service conditions or even modify displayed images on affected devices.

The CVSS v3.1 score for this vulnerability is a high 8.8, with a CVSS v4.0 score of 8.7, underscoring the severity of the potential impact. The attack vector is network-based, requires low complexity, and can be performed with limited privileges, making it accessible to a wide range of threat actors.

PayRange, the vendor behind the affected API, has not yet responded to CISA's requests to develop and implement mitigations for this vulnerability. This lack of vendor response leaves users of PayRange devices in a precarious position, with no immediate patches or official guidance available to address the security gap.

CISA strongly recommends that users of PayRange devices take defensive measures to minimize the risk of exploitation. These measures include minimizing network exposure for all control system devices, ensuring they are not directly accessible from the internet, and locating them behind firewalls and isolated from business networks. When remote access is necessary, CISA advises using secure methods like Virtual Private Networks (VPNs), while also emphasizing the importance of keeping VPNs updated.

While no public exploitation of this specific vulnerability has been reported to CISA at this time, the critical nature of the flaw and its potential for widespread impact warrant immediate attention from organizations utilizing PayRange systems. The advisory serves as a crucial alert for critical infrastructure sectors, particularly commercial facilities, where PayRange devices are deployed in the United States and Canada.

Organizations are encouraged to contact PayRange customer support for any available information or potential workarounds. CISA also reminds users to perform thorough impact analyses and risk assessments before deploying any defensive measures and to report any suspected malicious activity to CISA for correlation and tracking.

Synthesized by Vypr AI