Executive brief
Universal Software Inc. UKBS, a business software solution, contains a security flaw where critical functions do not require proper authentication. This allows an attacker on the same local network to access sensitive administrative features and data without a password. Because the product is no longer supported by the vendor, no official security updates will be released to fix this issue.
Technical details
A vulnerability classified as CWE-306 (Missing Authentication for Critical Function) exists in Universal Software Inc. UKBS through version 28072026. The application fails to enforce authentication or access control lists (ACLs) on sensitive functional endpoints. An unauthenticated attacker with adjacent network access can exploit this to execute privileged operations, potentially leading to a full compromise of the system's confidentiality, integrity, and availability. The vendor has confirmed the product is end-of-life (EOL) and no patch is available.
Affected products
- Universal Software Inc. UKBS through 28072026
Timeline
- 2026-07-28: advisory: NVD publication date
- 2026-07-28: disclosed: Vendor confirmed product is not supported