CVE-2026-28409Disclosure(wegia / wegia)

LOWCVSS 7.2 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch wegia wegia systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, a critical Remote Code Execution (RCE) vulnerability exists in the WeGIA application's database restoration functionality. An attacker with administrative access (which can be obtained via the previously reported Authentication Bypass) can execute arbitrary OS commands on the server by uploading a backup file with a specifically crafted filename. Version 3.6.5 fixes the issue.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • wegia

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 8 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 8 signals
  • Disclosure: 5 classified signals
  • Peaked 3d ago at 3 mentions (2026-02-28); latest day: 1
  • 8 total mentions across 5 days

Affected systems

Vendors
Products
wegia

Deep dive

Activity timeline8 mentions / 5d
01223Mentions · 2026-02-27: 2Mentions · 2026-02-28: 3Mentions · 2026-03-02: 1Mentions · 2026-03-04: 1Mentions · 2026-04-21: 1PoC Mentioned / Linked · 2026-04-21: 1Patch / Workaround · 2026-02-27: 1Patch / Workaround · 2026-02-28: 1Patch / Workaround · 2026-03-02: 1Technical Details · 2026-02-27: 2Technical Details · 2026-02-28: 3Technical Details · 2026-03-02: 1Technical Details · 2026-03-04: 1Technical Details · 2026-04-21: 102-2702-2803-0203-0404-21
Signal classification2 categories
Disclosure
562.5%
Patch
337.5%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-02-272
Disclosure1Patch1
2026-02-283
Disclosure2Patch1
2026-03-021
Patch1
2026-03-041
Disclosure1
2026-04-211
Disclosure1
Full discourse8 posts
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-28409 - critical 🚨 WeGIA <= 3.6.4 - Remote Code Execution > WeGIA <= 3.6.5 contains a remote code execution caused by improper validation of back... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-28409 @pdnuclei #NucleiTemplates #cve

    Post summary

    The post announces CVE-2026-28409, a critical RCE vulnerability in WeGIA versions up to 3.6.4/5, and links to ProjectDiscovery for further details.

    00011131
    942 followersView on X
  • maru@maru1151157
    Patch

    🚨 CVE-2026-28409 (CVSS: 10.0) WeGIAのデータベース復元機能にRCE脆弱性。管理者アクセス可能場合、カスタムファイル名でバックアップアップロードにより任意のOSコマンド実行可能。バージョン3.6.5で修正。 https://maruomosquit.com/vulnerability/CVE-2026-28409/ #脆弱性 #セキュリティ

    Post summary

    CVE-2026-28409 is a critical RCE in WeGIA's database restore feature, fixed in version 3.6.5; no active exploitation or PoC reported.

    00010142
    1.4K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-28409 - Critical WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, a critical Remote Code Execution (RCE) vulnerability exists in the WeGIA application's database restoration fun... https://www.thehackerwire.com/vulnerability/CVE-2026-28409/ https://t.co/56kvjUtNKI

    Post summary

    The post announces a critical RCE vulnerability (CVE-2026-28409) in WeGIA before version 3.6.5, providing basic technical details but no PoC, exploit, patch, or evidence of active exploitation.

    1000072
    119 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-28409 (CVSS:10.0, CRITICAL) is Analyzed. WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, a critical Remote Code Execution (RCE) vulne..https://nvd.nist.gov/vuln/detail/CVE-2026-28409 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE-2026-28409, a critical RCE vulnerability in WeGIA prior to v3.6.5, with CVSS 10.0, but provides no exploit, patch, or active exploitation details.

    0000043
    173 followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    A critical RCE vulnerability (CVE-2026-28409) affecting `WeGIA` via OS command injection has been patched. Upgrade `WeGIA` to the latest fixed version. #WeGIA #RCE #InfoSec https://www.pulsepatch.io/posts/cve-2026-28409-wegia-remote-code-execution

    Post summary

    The post announces that CVE‑2026‑28409, a critical OS command injection RCE in WeGIA, has been patched and urges users to upgrade to the latest version.

    0000060
    1 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-28409 WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, a critical Remote Code Execution (RCE) vulnerability exists in the WeGIA application's dat… https://www.cve.org/CVERecord?id=CVE-2026-28409

    Post summary

    The text announces a critical RCE vulnerability in WeGIA before version 3.6.5, providing basic technical details but no exploitation or mitigation information.

    00000157
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-28409 Remote Code Execution in WeGIA Web Manager Prior to Version 3.6.5 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-28409

    Post summary

    The text announces a remote code execution vulnerability affecting WeGIA Web Manager versions earlier than 3.6.5, with no additional exploitation details.

    0000058
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-28409: CRITICAL] Web manager WeGIA had a critical RCE vulnerability in versions before 3.6.5, allowing attackers to execute commands by uploading a malicious file. Update to secure your system.#cve,CVE-2026-28409,#cybersecurity https://cvefind.com/CVE-2026-28409

    Post summary

    A critical RCE vulnerability (CVE‑2026‑28409) affects WeGIA versions before 3.6.5, enabling attackers to execute commands by uploading a malicious file; users are urged to update to mitigate the risk.

    0000062
    585 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwegiawegia---

Explore more