CVE-2026-1621
Received Received - Intake

Authentication Bypass in E-Municipality via Trusted Identifier

Vulnerability report for CVE-2026-1621, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-14

Last updated on: 2026-08-14

Assigner: Computer Emergency Response Team of the Republic of Turkey

Description

Authentication bypass by primary weakness vulnerability in Universal Software Inc. E-Municipality allows Exploitation of Trusted Identifiers. This issue affects E-Municipality: from 20251127 before 20260204.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-14
Last Modified
2026-08-14
Generated
2026-08-14
AI Q&A
2026-08-14
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
universal_software_inc e-municipality From 20251127 (inc) to 20260204 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-305 The authentication algorithm is sound, but the implemented mechanism can be bypassed as the result of a separate weakness that is primary to the authentication error.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an authentication bypass issue in Universal Software Inc. E-Municipality software. It allows attackers to bypass authentication mechanisms by exploiting weaknesses in trusted identifiers, potentially gaining unauthorized access to the system.

Impact Analysis

An attacker could exploit this to impersonate legitimate users, access sensitive data, or perform unauthorized actions. Since the system is used for municipal services, this could disrupt public services or lead to data breaches affecting citizens.

Compliance Impact

This vulnerability could lead to unauthorized access to personal data, violating GDPR and HIPAA requirements for data protection and access controls. Organizations using this software may face compliance violations and legal penalties.

Mitigation Strategies

Update E-Municipality to a version after 20260204 to address the authentication bypass vulnerability. Monitor network traffic for unusual authentication patterns or trusted identifier exploitation attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-1621. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart