Unauthenticated Endpoint Vulnerability in WeGIA for Charitable Institutions
CVE-2026-54767
9.1CRITICAL
What is CVE-2026-54767?
WeGIA, a web management tool for charitable institutions, has a vulnerability that exposes an unauthenticated GET endpoint. Prior to version 3.8.5, a hardcoded chave_correta value was used to allow access, enabling remote attackers to execute TRUNCATE TABLE operations on critical tables like endereco, pessoafisica, pessoajuridica, and socio. This exploitation results in the permanent deletion of essential member and contributor records, underscoring serious risks to data integrity. The issue is mitigated in version 3.8.5.
Affected Version(s)
WeGIA < 3.8.5
