Unauthorized Data Injection in WeGIA by LabRedesCefetRJ
CVE-2026-28408
9.8CRITICAL
What is CVE-2026-28408?
WeGIA, a web management tool designed for charitable organizations, contains a security vulnerability in the file adicionar_tipo_docs_atendido.php prior to version 3.6.5. This issue allows unauthorized users to bypass the central controller of the application, circumventing necessary authentication and permission checks. As a result, malicious actors can exploit this flaw to make direct requests using utilities like Postman or by accessing the file’s URL. Such exploitation could enable unauthorized parties to inject large volumes of data into the application server's storage system, posing significant risks to sensitive information management.
Affected Version(s)
WeGIA < 3.6.5
