CVE-2026-11944: OS4ED Opensis
Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.
openSIS Classic 9.3 contains an authenticated path traversal vulnerability in the legacy messaging sent-mail attachment download functionality that allows an authenticated attacker to read arbitrary files on the server via crafted path traversal sequences.
Affected products
- OS4ED Opensis: version 9.3 only
Published 2026-07-14. Last modified 2026-07-14.