SQL injection in WeGIA - CVE-2026-55684

 

SQL injection in WeGIA - CVE-2026-55684

Published: July 7, 2026


Vulnerability identifier: #VU136987
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-55684
CWE-ID: CWE-89
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary SQL commands.

The vulnerability exists due to SQL injection in html/socio/sistema/cadastro_cobrancas_geracao.php when handling POST requests to /html/socio/sistema/cadastro_cobrancas_geracao.php. A remote attacker can send a specially crafted request with malicious parameter values to execute arbitrary SQL commands.

The issue affects multiple POST parameters, including both unquoted integer fields and string fields that can break out of single-quoted SQL context.


Affected software

WeGIA

How to mitigate CVE-2026-55684

Install security update from vendor's website.

WeGIA - update to 3.8.6

External References

Related Security Bulletins