Incorrect authorization in WeGIA - #VU136997
Published: July 7, 2026
Vulnerability details
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to improper access control in web/controle/control.php and FuncionarioControle permission-management methods when dispatching controller methods. A remote user can send a crafted request to modify permissions assigned to arbitrary roles and escalate privileges.
Exploitation requires authentication, a valid CSRF token from the attacker's own session, and an existing permission entry for resource 11 or 91.