Path traversal in WeGIA - CVE-2026-54670

 

Path traversal in WeGIA - CVE-2026-54670

Published: July 7, 2026


Vulnerability identifier: #VU136976
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-54670
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to path traversal in web/html/contribuicao/controller/control.php when processing the nomeClasse parameter in POST requests to /html/contribuicao/controller/control.php. A remote attacker can supply a crafted controller path to disclose sensitive information.

The issue can be exploited without authentication, and included files may expose configuration data and PHP source files.


Affected software

WeGIA

How to mitigate CVE-2026-54670

Install security update from vendor's website.

WeGIA - update to 3.8.5

External References

Related Security Bulletins