Use of hard-coded credentials in WeGIA - CVE-2026-54767

 

Use of hard-coded credentials in WeGIA - CVE-2026-54767

Published: July 7, 2026


Vulnerability identifier: #VU136977
CSH Severity: High
CVSS v4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-54767
CWE-ID: CWE-798
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause mass data destruction.

The vulnerability exists due to use of hard-coded credentials and missing authentication for a critical function in the deletar_socios.php endpoint when handling a crafted GET request with the chave parameter. A remote attacker can supply the exposed secret key to trigger deletion of database records and tables to cause mass data destruction.

The secret key is publicly visible in the source repository.


Affected software

WeGIA

How to mitigate CVE-2026-54767

Install security update from vendor's website.

WeGIA - update to 3.8.5

External References

Related Security Bulletins