# PayRange API exposes vending device data

Published: 2026-08-25 · Severity: routine · Sectors: retail
Canonical: https://vorant.io/reports/d8efff5b-f738-5ed7-8940-6bafa81ef761/payrange-api-exposes-vending-device-data

> A missing-authorization flaw in PayRange's API publicly exposes device details on payment/vending terminals, with no vendor fix available.

CISA has published an advisory for CVE-2026-18965, a missing authorization vulnerability (CWE-862) in the PayRange API that affects all versions. The flaw allows a remote attacker, authenticated or not, to access verbose management-endpoint details for every device on a PayRange network without needing valid credentials. Depending on how the information is leveraged, this could enable disclosure of sensitive data, denial of service against affected devices, or unauthorized alteration of a device's displayed image.

PayRange devices are deployed primarily in the Commercial Facilities sector across the United States and Canada, commonly powering unattended vending and payment kiosks. CISA notes that PayRange has not responded to coordination requests to remediate the issue, so no patch or update is currently available. There is no evidence of active exploitation in the wild as of publication.

Defenders operating PayRange-connected devices should treat the affected management endpoints as untrusted and apply standard ICS network-hardening guidance: eliminate direct internet exposure of control system devices, place them behind firewalls and segment them from business networks, and use VPNs for any required remote access while keeping VPN software current. Given the vendor's non-responsiveness, organizations should also contact PayRange support directly and monitor for any future guidance or unofficial mitigations.

## Mentioned in this report

- Vulnerabilities: CVE-2026-18965

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-04

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/d8efff5b-f738-5ed7-8940-6bafa81ef761/payrange-api-exposes-vending-device-data.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
