Authorization bypass through user-controlled key in WeGIA - #VU136989

 

Authorization bypass through user-controlled key in WeGIA - #VU136989

Published: July 7, 2026


Vulnerability identifier: #VU136989
CSH Severity: Medium
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-639
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to access, modify, or delete arbitrary user records.

The vulnerability exists due to improper access control in /controle/control.php and multiple Controle classes when handling POST requests with user-controlled record identifiers via extract($_REQUEST). A remote user can supply crafted id parameters to access, modify, or delete arbitrary user records.

The issue affects multiple CRUD methods across AtendidoControle, InternoControle, FuncionarioControle, and VoluntarioControle.


Affected software

WeGIA

Remediation

Install security update from vendor's website.

WeGIA - update to 3.8.7

External References

Related Security Bulletins