Junglewise Threat Intelligence

CVE-2026-6792: Universal Software Inc. FlexCity missing authorization in access control

CVE-2026-6792 · Severity: medium · CVSS 6.5 · Published 2026-07-21

Vendors: Universal Software Inc..

Executive brief

A security flaw has been identified in Universal Software Inc. FlexCity, a platform used for smart city management and urban automation. The vulnerability involves a failure to properly check user permissions, which could allow an authorized user to access sensitive information they are not supposed to see. This could lead to the exposure of private city data or administrative records, potentially impacting operational privacy and data security.

Technical details

A missing authorization vulnerability (CWE-862) exists in Universal Software Inc. FlexCity versions 5.536.0 through 11052026. The flaw stems from incorrectly configured access control security levels, which fail to properly validate user permissions for specific actions or data requests. An attacker with low-privileged network access can exploit this to gain unauthorized access to sensitive information (High Confidentiality impact). The attack vector is network-based and does not require user interaction, though it does require basic authenticated access (PR:L).

Affected products

  • Universal Software Inc. FlexCity 5.536.0 through 11052026

Timeline

  • 2026-07-21: advisory: NVD published the vulnerability details.

References