OpenSIS Classic Vulnerability for Teacher Role Affects Password Security
CVE-2026-91107

9.3CRITICAL

Key Information:

Vendor

Os4ed

Vendor
CVE Published:
5 October 2026

What is CVE-2026-91107?

In openSIS Classic 9.3, an authenticated user with a teacher role can exploit a flaw that allows them to select any staff record by manipulating the staff_id parameter. This action leads to unauthorized password resets for selected accounts, thereby compromising the security of the system and potentially exposing sensitive information. This vulnerability necessitates immediate attention to secure account management in school information systems.

Affected Version(s)

openSIS-Classic Windows 9.3

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Daniel Celis
.