CVE-2026-18965EPSS p21.0%
CVE-2026-18965CVE-2026-18965
Description
PayRange API is missing proper authorization on management endpoints, which allows verbose details of every device on the PayRange network to be publicly accessible, with or without an account.
Scoring
| CVSS | 8.8 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 0.30% probability of exploitation · percentile 21.0% · 2026-10-05T12:00:23Z |
| Last modified | 2026-08-31 |