CVE-2026-1619

Authorization Bypass Through User-Controlled Key vulnerability in Universal Software Inc. FlexCity/Kiosk allows Exploitation of Trusted Identifiers. This issue affects FlexCity/Kiosk: from 1.0 before 1.0.36.

high 8.3 CVSS 3.1
Published: Feb 13, 2026
Modified: Jun 6, 2026
Vendor: Uni-Yaz
Product: Flexcity