CVE-2026-11944
MEDIUMopenSIS Classic 9.3 - Authenticated path traversal in SentMail attachment download
Title source: cnaDescription
openSIS Classic 9.3 contains an authenticated path traversal vulnerability in the legacy messaging sent-mail attachment download functionality that allows an authenticated attacker to read arbitrary files on the server via crafted path traversal sequences.
References (2)
Core 2
Core References
Third Party Advisory third-party-advisory
https://fluidattacks.com/es/advisories/toto
Product product
https://github.com/OS4ED/openSIS-Classic
Scores
CVSS v3
6.5
EPSS
0.0038
EPSS Percentile
30.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-22
Status
published
Products (2)
os4ed/opensis
9.3
OS4ED/openSIS-Classic
9.3
Published
Jul 14, 2026
Tracked Since
Jul 14, 2026