Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.3

FlexCity/Kiosk: Unauthorized Access to Trusted Data

CVE-2026-1619
Summary

A security issue in FlexCity/Kiosk software allows an attacker to gain access to sensitive information that they shouldn't have access to. This affects all versions of FlexCity/Kiosk prior to 1.0.36. To stay protected, update to the latest version of FlexCity/Kiosk.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versionsFix available
uni-yaz flexcity > 1.0 , <= 1.0.36 –
Original title
Authorization Bypass Through User-Controlled Key vulnerability in Universal Software Inc. FlexCity/Kiosk allows Exploitation of Trusted Identifiers.This issue affects FlexCity/Kiosk: from 1.0 befor...
Original description
Authorization Bypass Through User-Controlled Key vulnerability in Universal Software Inc. FlexCity/Kiosk allows Exploitation of Trusted Identifiers.This issue affects FlexCity/Kiosk: from 1.0 before 1.0.36.
nvd CVSS3.1 8.3
Vulnerability type
CWE-639 Authorization Bypass Through User-Controlled Key
Published: 13 Feb 2026 · Updated: 10 Mar 2026 · First seen: 6 Mar 2026