Description
Authorization bypass through User-Controlled key vulnerability in Universe Software Computer Marketing Trade and Industry Inc. Online Registration and Workflow Management System allows Exploiting Trust in Client.

This issue affects Online Registration and Workflow Management System: through 12022026.
Published: 2026-07-22
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an IDOR flaw that permits an attacker to bypass authorization by providing a user‑controlled key. This flaw allows a legitimate user to access or modify resources that should be restricted, potentially exposing confidential data or enabling unauthorized manipulation of workflow information. The weakness corresponds to CWE‑639, indicating an authorization bypass through a user‑controlled key.

Affected Systems

The affected product is Universe Software Computer Marketing Trade and Industry Inc. Online Registration and Workflow Management System, with all releases up to version 12022026. No other vendors or products are listed.

Risk and Exploitability

The CVSS score of 6.5 places this flaw in the moderate-to-high severity range, while an EPSS of less than 1% indicates a low current likelihood of exploitation but does not preclude the possibility. The flaw is not listed in the CISA KEV catalog, suggesting no known widespread exploitation to date. The likely attack vector involves client‑side manipulation of a key that governs access to protected resources, allowing an attacker with knowledge of the key structure to retrieve or modify data they should not normally access.

Generated by OpenCVE AI on August 4, 2026 at 00:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check for and apply any vendor‑released patch or update for the Online Registration and Workflow Management System.
  • If a patch is not yet available, implement server‑side validation that verifies the authenticity and authorization level of the key before granting access to any protected resource.
  • Configure the system to restrict or disable the self‑service registration or workflow features that expose the vulnerable key handling to end users.

Generated by OpenCVE AI on August 4, 2026 at 00:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Universe Software Computer Marketing Trade And Industry
Universe Software Computer Marketing Trade And Industry online Registration And Workflow Management System
Vendors & Products Universe Software Computer Marketing Trade And Industry
Universe Software Computer Marketing Trade And Industry online Registration And Workflow Management System

Wed, 22 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Description Authorization bypass through User-Controlled key vulnerability in Universe Software Computer Marketing Trade and Industry Inc. Online Registration and Workflow Management System allows Exploiting Trust in Client. This issue affects Online Registration and Workflow Management System: through 12022026.
Title IDOR in Universe Software's Online Registration and Workflow Management System
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Universe Software Computer Marketing Trade And Industry Online Registration And Workflow Management System
cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-08-05T14:25:47.433Z

Reserved: 2026-02-12T13:25:58.515Z

Link: CVE-2026-2406

cve-icon Vulnrichment

Updated: 2026-08-05T14:25:08.219Z

cve-icon NVD

Status : Deferred

Published: 2026-07-22T09:16:28.903

Modified: 2026-08-05T15:16:46.927

Link: CVE-2026-2406

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T00:15:04Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key