CRITICAL 9.3 NVD
CVE-2026-91107
openSIS Classic 9.3 allows an authenticated user with the built-in teacher role can select an arbitrary staff record through staff_id and cause the School Infor
openSIS Classic 9.3 allows an authenticated user with the built-in teacher role can select an arbitrary staff record through staff_id and cause the School Information update path to reset that selected account's password.
References
- https://fluidattacks.com/advisories/hearts
- https://github.com/OS4ED/openSIS-Classic
- https://github.com/OS4ED/openSIS-Classic/commit/24bb530391a67c114cd4fe3dff65da7e070f5ed1
This critical severity vulnerability with a CVSS score of 9.3 was published on 2026-10-05 via NVD.
Risk Timeline
CVE Disclosed2026-10-05 · 0 days ago
Remediation Resources
vulnfeed aggregates 7729 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.