OS Command Injection in WeGIA - CVE-2026-55679
Published: July 7, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary commands.
The vulnerability exists due to command injection in web/instalador/instalador.php when processing unauthenticated installer POST data in the Linux reinstall flow. A remote attacker can send a specially crafted request to execute arbitrary commands.
The endpoint is reachable before config.php exists in pre-installation scenarios.