OpenSIS Classic Vulnerability for Teacher Role Affects Password Security
CVE-2026-91107
9.3CRITICAL
What is CVE-2026-91107?
In openSIS Classic 9.3, an authenticated user with a teacher role can exploit a flaw that allows them to select any staff record by manipulating the staff_id parameter. This action leads to unauthorized password resets for selected accounts, thereby compromising the security of the system and potentially exposing sensitive information. This vulnerability necessitates immediate attention to secure account management in school information systems.
Affected Version(s)
openSIS-Classic Windows 9.3
