Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 05 Oct 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | openSIS Classic 9.3 allows an authenticated user with the built-in teacher role can select an arbitrary staff record through staff_id and cause the School Information update path to reset that selected account's password. | |
| Title | openSIS Classic 9.3 - Insecure Direct Object Reference (IDOR) | |
| First Time appeared |
Os4ed
Os4ed opensis-classic |
|
| Weaknesses | CWE-639 | |
| CPEs | cpe:2.3:a:os4ed:opensis-classic:9.3:*:linux:*:*:*:*:* cpe:2.3:a:os4ed:opensis-classic:9.3:*:macos:*:*:*:*:* cpe:2.3:a:os4ed:opensis-classic:9.3:*:windows:*:*:*:*:* |
|
| Vendors & Products |
Os4ed
Os4ed opensis-classic |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Fluid Attacks
Published:
Updated: 2026-10-05T21:29:29.268Z
Reserved: 2026-09-14T19:25:23.243Z
Link: CVE-2026-91107
No data.
Status : Received
Published: 2026-10-05T22:16:58.657
Modified: 2026-10-05T22:16:58.657
Link: CVE-2026-91107
No data.
OpenCVE Enrichment
Updated: 2026-10-05T22:30:19Z
-
CWE-639
Authorization Bypass Through User-Controlled Key