CVE-2026-18965 describes a missing authorization vulnerability in the PayRange API, specifically affecting its management endpoints. The flaw allows verbose details of every device on the PayRange network to be publicly accessible without requiring authentication or an account. This represents a significant information disclosure risk, as sensitive device data across the entire PayRange network is exposed. The vulnerability has been reported via NVD and is accompanied by a CISA ICS advisory (ICSA-26-237-04), indicating its relevance to operational technology and critical infrastructure environments. The lack of proper access controls on management APIs is a critical security gap that could facilitate reconnaissance and further attacks.