# CVE-2026-68484

## Summary

- **CVE ID:** CVE-2026-68484
- **Severity:** CRITICAL
- **CVSS Score:** 9 (CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H)
- **CWE:** CWE-862
- **Published:** Sep 9, 2026
- **Last Modified:** Sep 9, 2026

## Description

Cash Collect contains an improper authorization vulnerability in the Sage AR Automation API. Administrative functions do not properly verify user privileges, allowing authenticated low-privileged users to create administrator accounts and obtain elevated privileges.

## Affected Products

- Sage — Sage AR Automation (June-R1-2026)

## References

- [CNA](https://helpcenter.sara.sage.com/hc/en-us/articles/52106283946651-June-R2-Release-2026)

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._