CVE-2026-11944

Severity CVSS v4.0:
MEDIUM
Type:
CWE-22 Path Traversal
Publication date:
14/07/2026
Last modified:
14/07/2026

Description

openSIS Classic 9.3 contains an authenticated path traversal vulnerability in the legacy messaging sent-mail attachment download functionality that allows an authenticated attacker to read arbitrary files on the server via crafted path traversal sequences.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:os4ed:opensis:9.3:*:*:*:community:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*