CVE-2026-1619
8.3Universal Software · FlexCity/Kiosk
An authorization bypass vulnerability in Universal Software FlexCity/Kiosk allows authenticated users to manipulate trusted identifiers to gain unauthorized access.
Executive summary
An authorization bypass vulnerability in Universal Software FlexCity/Kiosk permits authenticated users to elevate privileges and gain unauthorized access to system functions.
Vulnerability
The flaw is an authorization bypass (CWE-639) triggered by user-controlled keys. The CVSS vector indicates that a low-privileged authenticated user can achieve high impacts on confidentiality and integrity via a network-based attack.
Business impact
This vulnerability poses a significant risk to business operations by allowing authenticated users to bypass security controls and potentially access sensitive data or perform unauthorized administrative actions. Given the CVSS score of 8.3, this is categorized as a high-severity issue that could lead to full system compromise or data exfiltration if exploited by a malicious actor within the user base.
Remediation
Immediate Action: Update all instances of Universal Software FlexCity/Kiosk to version 1.0.36 or higher to resolve the authorization logic flaw.
Proactive Monitoring: Review access logs for suspicious patterns where low-privileged users are attempting to access administrative endpoints or functions outside their assigned roles.
Compensating Controls: Implement strict network segmentation and utilize a Web Application Firewall to block requests containing anomalous or tampered identifier keys.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Organizations utilizing the FlexCity/Kiosk platform must prioritize the upgrade to version 1.0.36 immediately. Because this vulnerability allows users to manipulate internal identifiers to gain unauthorized access, failing to patch leaves the environment open to privilege escalation and potential abuse of sensitive system capabilities.
More Universal Software CVEs
Sources
Originally found and disclosed by İbrahim YİĞİTSOY, per the CVE Program record.