Junglewise Threat Intelligence

CVE-2026-2406: Universe Software Online Registration and Workflow Management System auth bypass

CVE-2026-2406 · Severity: medium · CVSS 6.5 · Published 2026-07-22

Executive brief

A security flaw has been identified in the Universe Software Online Registration and Workflow Management System, a platform used for managing registrations and business processes. An authenticated user can bypass security controls to access information belonging to other users by manipulating identifiers in their web requests. This could lead to the unauthorized exposure of sensitive registration data and internal workflow records.

Technical details

The vulnerability is classified as CWE-639 (Authorization Bypass Through User-Controlled Key), occurring when the application trusts a user-provided identifier to access a record without verifying if the user has the appropriate permissions for that specific resource. An attacker with low-privileged credentials can modify parameters (such as IDs in a URL or POST request) to view or retrieve sensitive information belonging to other entities. The issue is present in versions up to and including 12022026. The attack is network-reachable and requires basic authentication but no user interaction.

Affected products

  • Universe Software Computer Marketing Trade and Industry Inc. Online Registration and Workflow Management System through 12022026

Timeline

  • 2026-07-22: advisory: NVD publication date
  • 2026-07-22: disclosed: TR-CERT advisory published

References