Description
uniFLOW Universal Login Manager (ULM) Standalone
contains an information disclosure vulnerability that may allow an
authenticated administrator to access sensitive configuration information
through the ULM Remote User Interface (RUI). Exploitation requires
administrative privileges and may disclose configuration data associated with
SMTP or LDAP integrations. ULM deployments connected to uniFLOW Server or
uniFLOW Online are not affected.
Published: 2026-07-06
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is caused by improper protection of sensitive configuration information in uniFLOW ULM Standalone. An attacker who has authenticated administrative privileges can retrieve confidential configuration details, specifically those relating to SMTP or LDAP integrations, through the ULM Remote User Interface. This disclosure enables potential credential compromise or further attacks, as the exposed settings may contain service credentials or addresses. The weakness is classified as CWE-522.

Affected Systems

The affected product is NT‑ware's uniFLOW ULM Standalone. No version specific data is listed in the advisory, and deployments that are connected to uniFLOW Server or uniFLOW Online are explicitly excluded from impact.

Risk and Exploitability

The CVSS score of 4.8 indicates moderate severity, while the EPSS score of less than 1% shows that the likelihood of exploitation is very low. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated administrator, so the risk depends largely on internal access controls. The potential impact is limited to disclosure of configuration data and does not affect authentication or execution of arbitrary code.

Generated by OpenCVE AI on July 26, 2026 at 20:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest vendor patch for uniFLOW ULM Standalone as soon as it is available.
  • If a patch cannot be applied immediately, restrict administrative access to the ULM Remote User Interface and enforce least‑privilege for administrators.
  • Reduce the attack surface by disabling or removing unused SMTP and LDAP integration settings.

Generated by OpenCVE AI on July 26, 2026 at 20:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Nt-ware
Nt-ware uniflow Ulm (universal Login Manager) Standalone
Vendors & Products Nt-ware
Nt-ware uniflow Ulm (universal Login Manager) Standalone

Mon, 06 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 06 Jul 2026 09:00:00 +0000

Type Values Removed Values Added
Description uniFLOW Universal Login Manager (ULM) Standalone contains an information disclosure vulnerability that may allow an authenticated administrator to access sensitive configuration information through the ULM Remote User Interface (RUI). Exploitation requires administrative privileges and may disclose configuration data associated with SMTP or LDAP integrations. ULM deployments connected to uniFLOW Server or uniFLOW Online are not affected.
Title uniFLOW Universal Login Manager (ULM) Standalone Improper Protection of Sensitive Information Leads to Information Disclosure
Weaknesses CWE-522
References
Metrics cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N'}


Subscriptions

Nt-ware Uniflow Ulm (universal Login Manager) Standalone
cve-icon MITRE

Status: PUBLISHED

Assigner: Canon_EMEA

Published:

Updated: 2026-07-06T18:54:02.174Z

Reserved: 2026-01-26T12:49:23.159Z

Link: CVE-2026-1433

cve-icon Vulnrichment

Updated: 2026-07-06T18:53:57.223Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T20:45:03Z

Weaknesses
  • CWE-522

    Insufficiently Protected Credentials