Junglewise Threat Intelligence

CVE-2026-1618: Universal Software Inc. FlexCity/Kiosk authentication bypass

CVE-2026-1618 · Severity: high · CVSS 8.8 · Published 2026-02-13

Technologies: Uni-Yaz Flexcity. Vendors: Universal Software Inc., Uni-Yaz.

Executive brief

Universal Software Inc. FlexCity/Kiosk, a platform used for managing smart city services and public kiosks, contains a security flaw that allows users to bypass standard login procedures. By exploiting an alternate communication path, a low-privileged user can gain administrative control over the system. This could lead to unauthorized access to sensitive citizen data, disruption of public services, or full system takeover.

Technical details

An authentication bypass vulnerability (CWE-288) exists in Universal Software Inc. FlexCity/Kiosk versions 1.0 through 1.0.35. The flaw allows an attacker to bypass primary authentication mechanisms by using an alternate path or channel within the application. This vulnerability is network-reachable and requires low-level authenticated access (PR:L) to exploit. Successful exploitation enables an attacker to escalate their privileges, potentially gaining full administrative access to the kiosk management system. The issue is addressed in version 1.0.36.

Affected products

  • Universal Software Inc. FlexCity/Kiosk 1.0 to 1.0.36

Timeline

  • 2026-02-13: disclosed
  • 2026-02-13: advisory

References

Related threats