# CVE-2026-67403

## Summary

- **CVE ID:** CVE-2026-67403
- **Severity:** CRITICAL
- **CVSS Score:** 9 (CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H)
- **CWE:** CWE-639
- **Published:** Sep 9, 2026
- **Last Modified:** Sep 9, 2026

## Description

Cash Collect contains an improper authorization vulnerability in the Sage AR Automation API. Insufficient tenant-level authorization checks allow authenticated users to access administrative resources belonging to other tenants by specifying a valid non predictable tenant identifier.

## Affected Products

- Sage — Sage AR Automation (June-R1-2026)

## References

- [CNA](https://helpcenter.sara.sage.com/hc/en-us/articles/52106283946651-June-R2-Release-2026)

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._