Missing Authentication for Critical Function in WeGIA - CVE-2026-28408

 

Missing Authentication for Critical Function in WeGIA - CVE-2026-28408

Published: April 23, 2026


Vulnerability identifier: #VU127320
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-28408
CWE-ID: CWE-306
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to inject unauthorized data.

The vulnerability exists due to improper access control in adicionar_tipo_docs_atendido.php when handling direct requests to the file URL. A remote attacker can send a specially crafted request to inject unauthorized data.

The script does not go through the project's central controller, allowing access to features exclusive to employees.


Affected software

WeGIA

How to mitigate CVE-2026-28408

Install security update from vendor's website.

WeGIA - update to 3.6.5

External References

Related Security Bulletins