Description
Missing Authorization vulnerability in Universal Software Inc. FlexCity allows Exploiting Incorrectly Configured Access Control Security Levels.

This issue affects FlexCity: from 5.536.0 before 5.542.0.
Published: 2026-07-21
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a missing authorization flaw that allows an attacker to bypass intended access controls in Universal Software Inc. FlexCity. This weakness can enable a user to acquire higher level privileges or access restricted resources (CWE‑862). The impact is a privilege‑escalation problem that threatens the confidentiality and integrity of the system and its data.

Affected Systems

Version 5.536.0 through just before 5.542.0 of Universal Software Inc. FlexCity are affected. No other editions or earlier releases are listed as vulnerable.

Risk and Exploitability

The CVSS score of 6.5 categorizes the flaw as moderate to high severity, but the EPSS score of less than 1 % indicates a very low likelihood of exploitation in the wild. The flaw is not included in the CISA KEV catalog. The attack vector is inferred to be through a web or management interface that is misconfigured or uses default credentials, permitting an attacker to elevate privileges or bypass restricted functionality.

Generated by OpenCVE AI on August 4, 2026 at 05:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade FlexCity to version 5.542.0 or later, or apply any vendor‑provided patch that addresses the authorization flaw.
  • Re‑evaluate all role‑based access controls, ensuring that permissions conform to the principle of least privilege and that no default or exceptional privileges remain enabled.
  • Conduct a comprehensive audit of all users, services, and processes to confirm that no unintended or overly broad permissions exist.

Generated by OpenCVE AI on August 4, 2026 at 05:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Universal Software Inc. FlexCity allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects FlexCity: from 5.536.0 through 11052026. Missing Authorization vulnerability in Universal Software Inc. FlexCity allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects FlexCity: from 5.536.0 before 5.542.0.

Mon, 27 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Universal Software Inc.
Universal Software Inc. flexcity
Vendors & Products Universal Software Inc.
Universal Software Inc. flexcity

Tue, 21 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Universal Software Inc. FlexCity allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects FlexCity: from 5.536.0 through 11052026.
Title Improper Authorization in Universal Sotware's FlexCity
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Universal Software Inc. Flexcity
cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-07-28T11:35:07.021Z

Reserved: 2026-04-21T13:50:29.886Z

Link: CVE-2026-6792

cve-icon Vulnrichment

Updated: 2026-07-21T16:27:38.429Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T06:00:05Z

Weaknesses