Description
Authentication bypass by primary weakness vulnerability in Universal Software Inc. E-Municipality allows Exploitation of Trusted Identifiers.

This issue affects E-Municipality: from 20251127 before 20260204.
Published: 2026-08-14
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a weakness in the authentication logic of Universal Software Inc. E‑Municipality that permits bypassing the normal registration process, enabling an attacker to assume privileged identities without proper credentials. This is a classic authentication bypass flaw, identified as CWE‑305, which undermines the integrity of the authentication system and permits unauthorized access to protected municipal services.

Affected Systems

Universal Software Inc. E‑Municipality build versions from 20251127 up to, but not including, 20260204 are impacted. These releases contain the vulnerable authentication flow that fails to enforce proper identity verification.

Risk and Exploitability

The CVSS score of 5.3 places the flaw in the medium severity range, suggesting a moderate impact if the flaw is successfully exploited. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, indicating that there is currently no evidence of widespread exploitation. The attack vector is not explicitly documented, but the nature of the flaw suggests remote exploitation via the public registration interface, making it potentially reachable over a network. Users should consider the risk of unauthorized privilege escalation when no patch or fix is applied.

Generated by OpenCVE AI on August 14, 2026 at 15:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor supplied patch or update to a version newer than build 20260204 that addresses the authentication bypass flaw.
  • Restrict access to the registration or authentication endpoints to trusted IP addresses or enforce multi‑factor authentication to reduce the attack surface.
  • Enable detailed logging and continuous monitoring of authentication events to detect anomalous activity and potential abuse of the bypass.

Generated by OpenCVE AI on August 14, 2026 at 15:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 14 Aug 2026 14:15:00 +0000

Type Values Removed Values Added
Description Authentication bypass by primary weakness vulnerability in Universal Software Inc. E-Municipality allows Exploitation of Trusted Identifiers. This issue affects E-Municipality: from 20251127 before 20260204.
Title Register Bypass in Universal Sotware's E-Municipality
Weaknesses CWE-305
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-08-14T14:37:12.458Z

Reserved: 2026-01-29T14:20:16.810Z

Link: CVE-2026-1621

cve-icon Vulnrichment

Updated: 2026-08-14T14:37:07.677Z

cve-icon NVD

Status : Received

Published: 2026-08-14T14:16:51.610

Modified: 2026-08-14T15:17:09.660

Link: CVE-2026-1621

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T15:30:03Z

Weaknesses
  • CWE-305

    Authentication Bypass by Primary Weakness