Junglewise Threat Intelligence

CVE-2026-1619: Universal Software Inc. FlexCity/Kiosk authorization bypass

CVE-2026-1619 · Severity: high · CVSS 8.3 · Published 2026-02-13

Technologies: Universal Software Inc. (Uni-Yaz) FlexCity Kiosk, Uni-Yaz Flexcity. Vendors: Universal Software Inc. (Uni-Yaz), Uni-Yaz.

Executive brief

Universal Software Inc. FlexCity/Kiosk, a platform used for city services and kiosk management, contains a security flaw that allows users to bypass authorization. By manipulating specific identifiers, an attacker can gain unauthorized access to data or functions they should not be able to reach. This could lead to the exposure of sensitive information or unauthorized changes to the system's operations.

Technical details

An Authorization Bypass Through User-Controlled Key (CWE-639) vulnerability exists in Universal Software Inc. FlexCity/Kiosk versions 1.0 through 1.0.36. The flaw allows a remote attacker with low privileges to bypass security checks by providing or manipulating trusted identifiers (such as account IDs or keys) within the application's requests. Successful exploitation enables the attacker to access or modify data belonging to other users or the system. The vulnerability is reachable over the network and has been addressed in version 1.0.36.

Affected products

  • Universal Software Inc. (Uni-Yaz) FlexCity/Kiosk 1.0 to 1.0.36

Timeline

  • 2026-02-13: advisory: Initial disclosure by TR-CERT
  • 2026-02-13: disclosed

References

Related threats