CVE-2026-8406: OS4ED Opensis-Classic
High severity, CVSS 7.1. EPSS: 0.4% chance of exploitation in the next 30 days.
openSIS Classic 9.3 contains an insecure direct object reference vulnerability in the messaging module. Any authenticated user with access to the messaging module can request sent-message details from modules/messaging/SentMail.php by supplying an arbitrary mail_id value.
Affected products
- OS4ED Opensis-Classic: version 9.3 only
Published 2026-06-11. Last modified 2026-06-17.