Authorization bypass through user-controlled key in WeGIA - CVE-2026-54671

 

Authorization bypass through user-controlled key in WeGIA - CVE-2026-54671

Published: July 7, 2026


Vulnerability identifier: #VU136975
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-54671
CWE-ID: CWE-639
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to access, modify, and delete arbitrary interno records and disclose sensitive information.

The vulnerability exists due to missing authorization in InternoControle and the permission check in MiddlewareDAO when handling POST requests to /controle/control.php with nomeClasse=InternoControle and user-controlled id parameters. A remote user can send a specially crafted request to access, modify, and delete arbitrary interno records and disclose sensitive information.

The issue affects all methods in InternoControle because an empty resource array causes unconditional access, and no ownership verification is performed on the referenced records.


Affected software

WeGIA

How to mitigate CVE-2026-54671

Install security update from vendor's website.

WeGIA - update to 3.8.5

External References

Related Security Bulletins