๐Ÿ” CVE Alert

CVE-2026-91107

UNKNOWN 0.0

openSIS Classic 9.3 - Insecure Direct Object Reference (IDOR)

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

openSIS Classic 9.3 allows an authenticated user with the built-in teacher role can select an arbitrary staff record through staff_id and cause the School Information update path to reset that selected account's password.

CWE CWE-639
Vendor os4ed
Product opensis-classic
Published Oct 5, 2026
Stay Ahead of the Next One

Get instant alerts for os4ed opensis-classic

Be the first to know when new unknown vulnerabilities affecting os4ed opensis-classic are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

OS4ED / openSIS-Classic
9.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
fluidattacks.com: https://fluidattacks.com/advisories/hearts github.com: https://github.com/OS4ED/openSIS-Classic github.com: https://github.com/OS4ED/openSIS-Classic/commit/24bb530391a67c114cd4fe3dff65da7e070f5ed1

Credits

Daniel Celis