CVE-2026-27189 | OpenSift up to 1.1.2-alpha/1.1.3-alpha auth toctou (GHSA-3pmp-j953-whxq)
A vulnerability was found in OpenSift up to 1.1.2-alpha/1.1.3-alpha and classified as problematic. This impacts an unknown function of the file sessions/study/quiz/flashcard/wellness/auth. Such manipulation leads to time-of-check time-of-use.
This vulnerability is documented as CVE-2026-27189. The attack needs to be performed locally. There is not any exploit available.
It is suggested to upgrade the affected component.