Executive brief
Universal Software Inc. FlexCity/Kiosk, a system used for managing municipal services and public kiosks, contains a security flaw that allows users to bypass access controls. An attacker with low-level access can perform administrative actions or access restricted functions without proper authentication. This could lead to unauthorized data access, service disruption, or full takeover of the kiosk management system.
Technical details
The vulnerability (CWE-267, CWE-306) in Universal Software Inc. FlexCity/Kiosk stems from missing authentication for critical functions and improperly defined access control lists (ACLs). A network-based attacker with low-privileged credentials can exploit these flaws to access administrative functionality and escalate their privileges within the application. The issue affects versions 1.0 through 1.0.35 and is resolved in version 1.0.36. The CVSS 3.1 score of 8.8 reflects high impact on confidentiality, integrity, and availability.
Affected products
- Universal Software Inc. (Uni-Yaz) FlexCity/Kiosk 1.0 to 1.0.36
Timeline
- 2026-02-13: disclosed: Initial publication of the vulnerability advisory
- 2026-02-13: advisory: Advisory published by TR-CERT (USOM)