PatchSiren

Universal Software Inc. CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Universal Software Inc. CVE published 2026-07-21

CVE-2026-8285

CVE-2026-8285 is a MEDIUM severity vulnerability in FlexCity, affecting versions from 5.536.0 before 5.542.0. The issue is an improper restriction of excessive authentication attempts, leading to Excessive Allocation. This vulnerability has a CVSS score of 4.3 and is classified as MEDIUM severity. Users of FlexCity versions from 5.536.0 before 5.542.0 should apply patches to prevent potential Excessive Al [truncated]

MEDIUM Universal Software Inc. CVE published 2026-07-21

CVE-2026-8284

A URL redirection to an untrusted site, also known as an 'open redirect,' vulnerability was found in Universal Software Inc.'s FlexCity product. This issue allows for Input Data Manipulation and has been classified as MEDIUM severity with a CVSS score of 6.1. The vulnerability affects FlexCity versions from 5.536.0 up to but not including 5.542.0. Administrators and users should be aware of this vulnerabi [truncated]

HIGH Universal Software Inc. CVE published 2026-02-13

CVE-2026-1619

CVE-2026-1619 is an Authorization Bypass Through User-Controlled Key vulnerability in FlexCity/Kiosk, allowing Exploitation of Trusted Identifiers. This issue affects FlexCity/Kiosk versions from 1.0 before 1.0.36.