External risk intelligence

openSIS Classic Teacher Password Reset Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-91107

openSIS is a web-based student information system designed to be accessed over the network by various user roles, including teachers. As a web-based application serving educational institutions, it is commonly deployed as an internet-facing or intranet-facing service accessible via standard web browsers, making the application interface a common point of network exposure.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability impacts openSIS Classic, a student information system, allowing authenticated teachers to reset the passwords of any staff member by manipulating a staff identifier. The main concern is confirming relevance and exposure within your environment.

  • Teachers can reset any staff password.
  • Critical student data system at risk.
  • Verify if your openSIS Classic is affected.

Attack Path

How an attacker could exploit the issue

An attacker with a teacher's account can access the school information update feature. By manipulating the staff ID, they can trigger a password reset for any staff account, potentially gaining unauthorized access to sensitive student data.

  • Authenticated teacher role required.
  • Arbitrary staff ID selection.
  • Unauthorized password reset and data access.

Live Threat

Current exploitation, exposure, and threat context

An authenticated teacher could reset any staff member's password by manipulating the `staff_id` parameter, potentially leading to unauthorized access to sensitive school information. This occurs when the system's password reset function is used to target specific staff accounts.

  • Staff account credentials.
  • Authenticated teacher manipulates `staff_id`.
  • Unauthorized access to staff accounts.

Operational Fix

Recommended remediation, mitigation, and detection steps

The School Information System owner, likely the IT or Application Support team, should lead the response to this vulnerability. The first practical step involves identifying all instances of openSIS Classic, confirming their network reachability and criticality, and then assigning ownership for remediation planning.

  • Identify affected systems and owners.
  • Verify external and internal reachability.
  • Plan remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is openSIS Classic?

openSIS Classic is a web-based student information system used by educational institutions to manage academic and administrative data. It organizes school operations by allowing various user roles, such as teachers and administrators, to access and update records through a central browser-based interface.

What does CWE-639 mean for CVE-2026-91107?

CWE-639, or Authorization Bypass Through User-Controlled Key, describes a flaw where an application relies on user-provided data to determine access permissions without verifying if the user is authorized to interact with that specific record. In CVE-2026-91107, this means the software incorrectly trusts a user-submitted staff ID, allowing an account holder to act on data belonging to others.

How is this password reset vulnerability triggered?

The issue is triggered when an authenticated user with a teacher role interacts with the School Information update feature and intentionally modifies the staff_id parameter. Merely logging into the teacher account or navigating the interface normally does not trigger the bug; the specific manipulation of the identifier is required to force the system to reset the password for an unintended staff account.

Do I need to worry about this if my system is internal?

Yes. According to Halo Surface Signal, while internet-facing instances have a clear network path for access, openSIS is also commonly deployed on intranet-facing services. Because the vulnerability is triggered by an already authenticated user, the internal nature of the application does not prevent the misuse of existing teacher accounts to perform unauthorized password resets.

When should I begin my response to this advisory?

You should prioritize this immediately by identifying all instances of openSIS Classic within your infrastructure. The first practical step is to confirm which systems are running the affected version, determine who owns the application support for those servers, and establish network reachability to begin remediation planning.

References