Executive brief
NT-ware uniFLOW Online is a device management solution used in multifunction printers and office equipment. A session management flaw in the Legacy UI's Reduced Function Login feature allows a previous user's authenticated session to persist after logout during Service Offline Emergency Mode, potentially enabling a subsequent user to gain unauthorized access to device functions with the privileges of the previous user.
Technical details
A session management vulnerability exists in the Legacy UI Reduced Function Login component of NT-ware uniFLOW Online where specific timing conditions during Service Offline Emergency Mode cause authenticated sessions to be retained after logout. An attacker requires local access to the device and specific conditions (Emergency Mode activation) to exploit this flaw; successful exploitation allows the attacker to access device functionality with the retained session credentials of a previously authenticated user.
Affected products
- NT-ware uniFLOW Online
Timeline
- 2026-09-23: disclosed