Use of hard-coded credentials in WeGIA - CVE-2026-54767
Published: July 7, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause mass data destruction.
The vulnerability exists due to use of hard-coded credentials and missing authentication for a critical function in the deletar_socios.php endpoint when handling a crafted GET request with the chave parameter. A remote attacker can supply the exposed secret key to trigger deletion of database records and tables to cause mass data destruction.
The secret key is publicly visible in the source repository.