CVE-2026-8406EPSS p15.0%

CVE-2026-8406CVE-2026-8406

Description

openSIS Classic 9.3 contains an insecure direct object reference vulnerability in the messaging module. Any authenticated user with access to the messaging module can request sent-message details from modules/messaging/SentMail.php by supplying an arbitrary mail_id value.

Scoring

EPSS0.24% probability of exploitation · percentile 15.0% · 2026-08-03T12:00:16Z
Last modified2026-06-11
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.