Remote Code Execution Vulnerability in WeGIA by LabRedesCefetRJ
CVE-2026-28409
10CRITICAL
What is CVE-2026-28409?
WeGIA, a web management tool for charitable organizations, has a vulnerability that enables remote code execution through its database restoration feature. An attacker with administrative access—potentially obtained through previous authentication bypass issues—can upload a malicious backup file with a specially designed filename. This action allows the attacker to execute arbitrary operating system commands on the server. Version 3.6.5 has been released to address this important security flaw.
Affected Version(s)
WeGIA < 3.6.5
