PayRange API Missing Authorization Vulnerability (CVE-2026-18965)
First seen Aug 27, 2026 · Updated Aug 27, 2026 · CVSS 8.8
PayRange API, used to manage internet-connected vending and payment devices, contains a missing authorization vulnerability that exposes verbose device management data to unauthenticated or authenticated attackers. Exploitation could allow information disclosure, denial of service, or manipulation of device-displayed content across the PayRange network. PayRange has not engaged with CISA to remediate the issue, leaving affected deployments exposed.
Technical Analysis
CVE-2026-18965 (CWE-862: Missing Authorization) affects all versions of the PayRange API, where management endpoints fail to enforce proper authorization checks, allowing any remote party to retrieve detailed device telemetry and status information across the PayRange network. The vulnerability carries a CVSS v3.1 score of 8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) and CVSS v4.0 score of 8.7, reflecting high impact to confidentiality, integrity, and availability with low attack complexity and no user interaction required. An attacker could leverage this exposure to disclose sensitive operational data, disrupt device functionality (denial of service), or alter displayed images/content on payment terminals. This is a commercial/IoT payment infrastructure vulnerability with no known public exploitation reported to date; it has no direct relevance to AI agent systems, LLM tool use, or RAG pipelines, as it is confined to vending/payment device management APIs rather than infrastructure typically used to host or support AI agents.
Affected Systems
PayRange API, all versions (vers:all/*), used in internet-connected vending and payment devices deployed primarily in the United States and Canada within the Commercial Facilities sector.
Indicators of Compromise
- No specific IOCs published; no known public exploitation reported at this time.
Remediation Steps
- 1
Restrict Network Exposure
Ensure PayRange devices and management interfaces are not accessible from the public internet; segment them behind firewalls and isolate from business networks.
- 2
Contact Vendor
Reach out to PayRange customer support (support@payrange.com) for guidance, as the vendor has not engaged with CISA on remediation.
- 3
Use Secure Remote Access
If remote access is required, use VPNs with up-to-date patching, recognizing VPN security is limited by the security of connected endpoints.
- 4
Monitor for Anomalous Activity
Watch for unauthorized access to device management endpoints or unexpected changes to device displays/status, and report suspicious activity to CISA.
- 5
Apply Defense-in-Depth
Follow CISA's ICS recommended practices, including network segmentation and layered security controls, to reduce risk until a vendor patch is available.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.