Unauthorized Data Injection in WeGIA by LabRedesCefetRJ
CVE-2026-28408
What is CVE-2026-28408?
WeGIA, a web management tool designed for charitable organizations, contains a security vulnerability in the file adicionar_tipo_docs_atendido.php prior to version 3.6.5. This issue allows unauthorized users to bypass the central controller of the application, circumventing necessary authentication and permission checks. As a result, malicious actors can exploit this flaw to make direct requests using utilities like Postman or by accessing the file’s URL. Such exploitation could enable unauthorized parties to inject large volumes of data into the application server's storage system, posing significant risks to sensitive information management.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WeGIA < 3.6.5
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
