Security Flaw Found in PayRange Payment API Could Expose Sensitive Data
A significant security flaw has been identified in the PayRange API, a system used to power vending and payment devices primarily across the United States and Canada. The vulnerability, tracked as CVE-2026-18965, stems from a 'Missing Authorization' issue and has received a high severity score of 8.8 out of 10.
According to CISA, the flaw could be exploited remotely by either an authenticated or unauthenticated attacker. If successfully exploited, it could allow sensitive information to be disclosed, cause a denial of service by disrupting device functionality, or let an attacker alter the image displayed on the affected device. All versions of the PayRange API are reportedly affected.
While this issue primarily affects commercial facilities using PayRange-connected devices, such as vending machines and unattended payment terminals, businesses using this technology should be aware of the risk. Organisations relying on third-party payment or vending APIs should stay alert for vendor updates and patches addressing this vulnerability.