Unauthorized Data Injection in WeGIA by LabRedesCefetRJ
CVE-2026-28408

9.8CRITICAL

Key Information:

Status
Vendor
CVE Published:
27 February 2026

What is CVE-2026-28408?

WeGIA, a web management tool designed for charitable organizations, contains a security vulnerability in the file adicionar_tipo_docs_atendido.php prior to version 3.6.5. This issue allows unauthorized users to bypass the central controller of the application, circumventing necessary authentication and permission checks. As a result, malicious actors can exploit this flaw to make direct requests using utilities like Postman or by accessing the file’s URL. Such exploitation could enable unauthorized parties to inject large volumes of data into the application server's storage system, posing significant risks to sensitive information management.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

WeGIA < 3.6.5

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.