Description
openSIS Classic 9.3 contains an authenticated path traversal vulnerability in the legacy messaging sent-mail attachment download functionality that allows an authenticated attacker to read arbitrary files on the server via crafted path traversal sequences.
Published: 2026-07-14
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in openSIS Classic 9.3 permits an authenticated attacker to read files located outside the intended directory by supplying crafted path traversal sequences in the legacy sent‑mail attachment download API. Because the application does not validate the path component supplied by the attacker, any file on the server that is readable by the web server process can be exfiltrated. The weakness is a classic directory traversal flaw (CWE‑22) that exposes confidentiality risks and can be used by a malicious user to compromise local secrets, configuration files, or system binaries.

Affected Systems

The product OS4ED’s openSIS Classic 9.3 on Linux, macOS, and Windows platforms is affected. The legacy messaging sent‑mail attachment download feature, when enabled and accessed by an authenticated user, allows exploitation. No versions before 9.3 are mentioned; the vulnerability exists only in release 9.3.

Risk and Exploitability

The CVSS score of 5.3 indicates medium severity, and the EPSS score below 1 % indicates low exploitation probability. The vulnerability is not listed in CISA KEV catalog. Exploitation requires valid authentication, so the attack surface is limited to legitimate users or compromised accounts. An attacker can obtain arbitrary files in the server’s file system and potentially pivot to further compromise the system.

Generated by OpenCVE AI on July 31, 2026 at 10:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to the latest stable release of openSIS Classic that contains the path traversal fix
  • Disable the legacy messaging sent‑mail attachment download feature if it is not required
  • Restrict user permissions to the minimal required roles, enforcing least‑privilege
  • Ensure file system permissions prevent the web server from reading sensitive directories

Generated by OpenCVE AI on July 31, 2026 at 10:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Description openSIS Classic 9.3 contains an authenticated path traversal vulnerability in the legacy messaging sent-mail attachment download functionality that allows an authenticated attacker to read arbitrary files on the server via crafted path traversal sequences.
Title openSIS Classic 9.3 - Authenticated path traversal in SentMail attachment download
First Time appeared Os4ed
Os4ed opensis-classic
Weaknesses CWE-22
CPEs cpe:2.3:a:os4ed:opensis-classic:9.3:*:linux:*:*:*:*:*
cpe:2.3:a:os4ed:opensis-classic:9.3:*:macos:*:*:*:*:*
cpe:2.3:a:os4ed:opensis-classic:9.3:*:windows:*:*:*:*:*
Vendors & Products Os4ed
Os4ed opensis-classic
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Os4ed Opensis-classic
cve-icon MITRE

Status: PUBLISHED

Assigner: Fluid Attacks

Published:

Updated: 2026-07-14T15:58:38.983Z

Reserved: 2026-06-10T21:25:07.392Z

Link: CVE-2026-11944

cve-icon Vulnrichment

Updated: 2026-07-14T15:58:35.077Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T10:15:06Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')