Privilege Escalation Vulnerability in Universal Software Inc. FlexCity/Kiosk
CVE-2025-14349

8.8HIGH

Key Information:

Vendor
CVE Published:
13 February 2026

What is CVE-2025-14349?

A privilege escalation vulnerability in Universal Software Inc.'s FlexCity/Kiosk allows attackers to access functionality without proper constraints enforced by Access Control Lists (ACLs). This could enable unauthorized access to critical functions, compromising the integrity and security of the system. Users of affected versions, prior to 1.0.36, are urged to review security practices and apply available updates to mitigate potential risks.

Affected Version(s)

FlexCity/Kiosk 1.0 < 1.0.36

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

İbrahim YİĞİTSOY
.