Description
Missing authentication for critical function vulnerability in Universal Software Inc. UKBS allows Accessing Functionality Not Properly Constrained by ACLs.

This issue affects UKBS: through 28072026.
NOTE: The vendor was contacted and it was learned that the product is not supported.
Published: 2026-07-28
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Universal Software Inc. UKBS suffers from a missing authentication requirement for a critical function. This flaw allows an attacker who can invoke the function to bypass normal access controls and gain unintended access to the system’s internal operations. The vulnerability is a classic authentication bypass (CWE‑306) that directly undermines confidentiality, integrity, and availability, potentially enabling further exploitation or privilege escalation.

Affected Systems

The affected product is Universal Software Inc. UKBS, with all releases up to and including version dated 28‑07‑2026 vulnerable. No specific sub‑versions are listed, so any build before that date should be considered at risk.

Risk and Exploitability

The CVSS score of 8.8 reflects high severity, and an EPSS score of less than 1% indicates that, while the feature is technically exploitable, the likelihood of active attacks remains very low at present. The vulnerability is not listed in CISA’s KEV catalog, suggesting it is not known to be actively exploited in the wild. The most probable attack vector involves remote users being able to call the exposed function over the network, but local or privileged attackers could also exploit the lack of authentication. Given the missing support notice, the opportunity for a vendor fix is absent, increasing the risk if the system remains exposed.

Generated by OpenCVE AI on August 3, 2026 at 15:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Disable or block external access to the vulnerable function through firewall rules or server configuration.
  • Implement or tighten ACLs to ensure only authorized users can invoke the function, even if the interface remains exposed.
  • Continuously monitor system logs for unusual invocation patterns of the critical function.
  • Plan to migrate to a supported version or alternative product when available.

Generated by OpenCVE AI on August 3, 2026 at 15:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Universal Software Inc.
Universal Software Inc. ukbs
Vendors & Products Universal Software Inc.
Universal Software Inc. ukbs

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Description Missing authentication for critical function vulnerability in Universal Software Inc. UKBS allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects UKBS: through 28072026. NOTE: The vendor was contacted and it was learned that the product is not supported.
Title Improper Authentication in Universal Sotware's UKBS
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Universal Software Inc. Ukbs
cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-08-04T18:58:26.674Z

Reserved: 2026-04-27T13:08:25.778Z

Link: CVE-2026-7187

cve-icon Vulnrichment

Updated: 2026-07-28T13:50:37.863Z

cve-icon NVD

Status : Deferred

Published: 2026-07-28T13:19:08.247

Modified: 2026-08-04T20:16:56.170

Link: CVE-2026-7187

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T15:15:04Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function