PT-2026-106256 · Os4Ed · Opensis Classic

·

CVE-2026-91107

·

Published

2026-10-05

·

Updated

2026-10-05

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
openSIS Classic 9.3 allows an authenticated user with the built-in teacher role can select an arbitrary staff record through staff id and cause the School Information update path to reset that selected account's password.

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-91107

Affected Products

Opensis Classic