Authorization Flaw in WeGIA Web Management Tool for Charitable Institutions
CVE-2026-54671

8.8HIGH

Key Information:

Status
Vendor
CVE Published:
17 September 2026

What is CVE-2026-54671?

WeGIA, a web management tool designed for charitable institutions, contains an authorization vulnerability that allows low-privileged users to access, modify, or delete records belonging to other users. This flaw arises due to improper handling of user permissions within the system, particularly in the methods related to InternoControle, which accept user-controlled values without adequate ownership checks. As a result, sensitive information such as personal identity, addresses, medical records, and family details could be exposed, creating significant privacy risks. This issue has been addressed in version 3.8.5.

Affected Version(s)

WeGIA < 3.8.5

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.