Unauthenticated Endpoint Vulnerability in WeGIA for Charitable Institutions
CVE-2026-54767

9.1CRITICAL

Key Information:

Status
Vendor
CVE Published:
17 September 2026

What is CVE-2026-54767?

WeGIA, a web management tool for charitable institutions, has a vulnerability that exposes an unauthenticated GET endpoint. Prior to version 3.8.5, a hardcoded chave_correta value was used to allow access, enabling remote attackers to execute TRUNCATE TABLE operations on critical tables like endereco, pessoafisica, pessoajuridica, and socio. This exploitation results in the permanent deletion of essential member and contributor records, underscoring serious risks to data integrity. The issue is mitigated in version 3.8.5.

Affected Version(s)

WeGIA < 3.8.5

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.