๐Ÿ” CVE Alert

CVE-2026-8406

UNKNOWN 0.0

openSIS Classic 9.3 - Insecure Direct Object Reference in Sent Mail

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

openSIS Classic 9.3 contains an insecure direct object reference vulnerability in the messaging module. Any authenticated user with access to the messaging module can request sent-message details from modules/messaging/SentMail.php by supplying an arbitrary mail_id value.

CWE CWE-639
Vendor os4ed
Product opensis-classic
Published Jun 11, 2026
Last Updated Jun 11, 2026
Stay Ahead of the Next One

Get instant alerts for os4ed opensis-classic

Be the first to know when new unknown vulnerabilities affecting os4ed opensis-classic are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

OS4ED / openSIS-Classic
9.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
fluidattacks.com: https://fluidattacks.com/es/advisories/melanie github.com: https://github.com/OS4ED/openSIS-Classic/commit/c45d43146167324bae06bdf09de3e4bd2e5e478f github.com: https://github.com/OS4ED/openSIS-Classic

Credits

Daniel Celis