OS Command Injection in WeGIA - CVE-2025-26613

 

OS Command Injection in WeGIA - CVE-2025-26613

Published: February 17, 2025 / Updated: May 2, 2026


Vulnerability identifier: #VU129024
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-26613
CWE-ID: CWE-78
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to improper neutralization of special elements used in an os command in the gerenciar_backup.php endpoint when handling the file parameter in POST requests. A remote attacker can send a specially crafted request to execute arbitrary code.

The issue can be exploited without being logged in because execution continues after the session check and redirect logic.


Affected software

WeGIA

How to mitigate CVE-2025-26613

Install security update from vendor's website.

WeGIA - update to 3.2.14

External References

Related Security Bulletins