Skip to content

Secure EU

Menu
  • Home
Menu

CVE-2025-14349 – Business Logic Error in Universal Software’s FlexCity/Kiosk

Posted on February 13, 2026
CVE ID : CVE-2025-14349

Published : Feb. 13, 2026, 1:09 p.m. | 52 minutes ago

Description : Privilege Defined With Unsafe Actions, Missing Authentication for Critical Function vulnerability in Universal Software Inc. FlexCity/Kiosk allows Accessing Functionality Not Properly Constrained by ACLs, Privilege Escalation.This issue affects FlexCity/Kiosk: from 1.0 before 1.0.36.

Severity: 8.8 | HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

Solution

©2026 Secure EU | Design: Newspaperly WordPress Theme