SQL injection in WeGIA - CVE-2026-23723

 

SQL injection in WeGIA - CVE-2026-23723

Published: April 23, 2026


Vulnerability identifier: #VU127301
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-23723
CWE-ID: CWE-89
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to SQL injection in the Atendido_ocorrenciaControle endpoint when handling the id_memorando parameter. A remote privileged user can send a specially crafted request to disclose sensitive information.

In misconfigured environments where the database FILE privilege is enabled, local file contents may also be exposed.


Affected software

WeGIA

How to mitigate CVE-2026-23723

Install security update from vendor's website.

WeGIA - update to 3.6.2

External References

Related Security Bulletins