CVE-2026-11944: OS4ED Opensis

Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.

openSIS Classic 9.3 contains an authenticated path traversal vulnerability in the legacy messaging sent-mail attachment download functionality that allows an authenticated attacker to read arbitrary files on the server via crafted path traversal sequences.

Affected products

  • OS4ED Opensis: version 9.3 only

Published 2026-07-14. Last modified 2026-07-14.