CVE-2026-28408Disclosure(wegia / wegia)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch wegia wegia systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, the script in adicionar_tipo_docs_atendido.php does not go through the project's central controller and does not have its own authentication and permission checks. A malicious user could make a request through tools like Postman or the file's URL on the web to access features exclusive to employees. The vulnerability allows external parties to inject unauthorized data in massive quantities into the application server's storage. Version 3.6.5 fixes the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287CWE-862

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • wegia

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 4 mentions (2026-02-28); latest day: 1
  • 7 total mentions across 3 days

Affected systems

Vendors
Products
wegia

Deep dive

Activity timeline7 mentions / 3d
01234Mentions · 2026-02-27: 2Mentions · 2026-02-28: 4Mentions · 2026-03-04: 1Patch / Workaround · 2026-02-27: 1Patch / Workaround · 2026-02-28: 1Technical Details · 2026-02-27: 1Technical Details · 2026-02-28: 3Technical Details · 2026-03-04: 102-2702-2803-04
Signal classification3 categories
Disclosure
457.1%
Patch
228.6%
General
114.3%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-02-272
Disclosure1Patch1
2026-02-284
Disclosure2General1Patch1
2026-03-041
Disclosure1
Full discourse7 posts
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-28408 (CVSS:9.8, CRITICAL) is Analyzed. WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, the script in adicionar_tipo_docs_atendido.p..https://nvd.nist.gov/vuln/detail/CVE-2026-28408 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE-2026-28408, a critical vulnerability in WeGIA’s script, but offers no PoC, exploit, or patch details.

    0000034
    173 followersView on X
  • The AI generalist@AIengineerlife
    Disclosure

    🚨 CVE-2026-28408 - CRITICAL WeGIA (Charitable Institution Manager) 🤖 AI Summary: CVE-2026-28408 is a critical authentication bypass vulnerability in WeGIA versions prior to 3.6.5, where t... ThreatScore: 95/100 🔗 http://threatmonitor.io/cve/cve-2026-28408 #cybersecurity #infosec #CVE

    Post summary

    This post announces CVE-2026-28408, a critical authentication bypass flaw in WeGIA versions before 3.6.5, noting a high threat score but providing no PoC, exploit code, or patch information.

    0000052
    9 followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    An authentication bypass (CVE-2026-28408) in `WeGIA` allows unauthenticated access to `adicionar_tipo_docs_atendido.php`. Patching to the fixed version is advised to mitigate this #AuthBypass #WebSecurity vulnerability. https://www.pulsepatch.io/posts/cve-2026-28408-wegia-authentication-bypass

    Post summary

    The post announces an authentication bypass vulnerability in WeGIA and recommends applying the fixed patch to mitigate the issue.

    0000068
    1 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-28408 WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, the script in adicionar_tipo_docs_atendido.php does not go through the project's central c… https://www.cve.org/CVERecord?id=CVE-2026-28408

    Post summary

    The text references CVE-2026-28408 in WeGIA but offers no concrete details, PoC, or mitigation information.

    00000127
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-28408 Unauthenticated Data Injection Vulnerability in WeGIA Web Manager... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-28408 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    A newly disclosed unauthenticated data injection vulnerability (CVE-2026-28408) in WeGIA Web Manager is referenced, with no PoC, exploit, or mitigation details provided.

    0000056
    4.0K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-28408 - Critical WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, the script in adicionar_tipo_docs_atendido.php does not go through the project's central controller and does no... https://www.thehackerwire.com/vulnerability/CVE-2026-28408/ https://t.co/JenluV08IQ

    Post summary

    A new critical vulnerability (CVE-2026-28408) was disclosed in the WeGIA web manager, affecting scripts before v3.6.5, but no proof‑of‑concept, exploit details, patch, or active exploitation evidence is provided.

    0000056
    119 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-28408: CRITICAL] Vulnerability in WeGIA web manager (pre-3.6.5) allowed unauthorized access. Update to version 3.6.5 to fix security flaw and prevent data breaches. #CyberSecurity#cve,CVE-2026-28408,#cybersecurity https://cvefind.com/CVE-2026-28408

    Post summary

    CVE-2026-28408 is a critical vulnerability in WeGIA web manager that permits unauthorized access; upgrading to version 3.6.5 mitigates the flaw.

    0000047
    585 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwegiawegia---

Explore more