Open redirect in WeGIA - CVE-2026-23729

 

Open redirect in WeGIA - CVE-2026-23729

Published: April 23, 2026


Vulnerability identifier: #VU127309
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-23729
CWE-ID: CWE-601
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to redirect users to arbitrary external websites.

The vulnerability exists due to url redirection to an untrusted site in the /WeGIA/controle/control.php endpoint when processing the nextPage parameter with metodo=listarDescricao and nomeClasse=ProdutoControle. A remote user can send a crafted request containing an external URL in the nextPage parameter to redirect users to arbitrary external websites.

User interaction is required for the redirect to occur.


Affected software

WeGIA

How to mitigate CVE-2026-23729

Install security update from vendor's website.

WeGIA - update to 3.6.2

External References

Related Security Bulletins