Insecure Direct Object Reference Vulnerability in WeGIA by LabRedesCefetRJ
CVE-2026-76634
7.1HIGH
What is CVE-2026-76634?
An insecure direct object reference vulnerability exists in WeGIA versions before 3.9.2. This flaw allows authenticated attackers to exploit the employee profile page, enabling access to arbitrary employee records. By injecting the 'id_pessoa' parameter through a request extraction function, attackers can override the session-derived identifier. Consequently, they can enumerate user identifiers to gain complete access to the profile data of any employee, which includes sensitive information such as names, CPF numbers, addresses, contact details, and administrative flags.
Affected Version(s)
WeGIA 0
