Universal Software FlexCity/Kiosk Authorization Bypass Vulnerability Allowing Exploitation of Trusted Identifiers

Vulnerability

An authorization bypass vulnerability has been identified in Universal Software Inc. FlexCity/Kiosk versions 1.0 prior to 1.0.36. This vulnerability allows for the exploitation of trusted identifiers, potentially leading to unauthorized actions or access within the application.

Impact

Exploitation of this vulnerability could allow attackers to bypass authorization controls, enabling them to manipulate trusted identifiers and possibly gain unauthorized access or privileges within the application.

Remediation

Users are advised to upgrade to version 1.0.36 or later.

Added: Feb 13, 2026, 2:48 PM
Updated: Feb 13, 2026, 2:48 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.3
exploitability
6.6
remediation
0.0
relevance
3.0
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.