The AI generalist[verified]@AIengineerlifeDisclosure
The post announces CVE-2026-28411, a critical authentication bypass in WeGIA web manager via an unsafe extract() function, enabling unauthenticated admin access, but it does not provide a PoC, exploit, or patch information.
OffSeq | Adversary Tactics for Cyber Resilience[verified]@offseqPatch
The post alerts to a critical authentication bypass (CVE‑2026‑28411) in LabRedesCefetRJ WeGIA versions <3.6.5, urges immediate patching to 3.6.5+, and provides no evidence of active exploitation or PoC.
OffSeq | Adversary Tactics for Cyber Resilience[verified]@offseqDisclosure
This alert announces the discovery of CVE-2026-28411, an authentication bypass vulnerability classified as CWE-288, without providing exploit details or patch information.
pdnuclei-bot@pdnuclei_botDisclosure
The post announces CVE-2026-28411 as a critical authentication bypass vulnerability in WeGIA < 3.6.5, providing a brief technical description but no PoC, exploit code, patches, or evidence of active exploitation.
The Hacker Wire@TheHackerWireDisclosure
CVE-2026-28411 is a critical vulnerability in WeGIA that exploits an unsafe `extract()` call on `$_REQUEST`, but no PoC, exploit code, patch, or active exploitation details are provided.
CRAC Learning - Tech@cracbotDisclosure
The post references CVE-2026-28411, noting its critical severity and unsafe use of extract() in WeGIA before v3.6.5, but provides no evidence of exploitation, PoC, or patch.
PulsePatch.io@pulsepatchioDisclosure
The post announces a critical authentication bypass vulnerability (CVE‑2026‑28411) in WeGIA caused by improper use of `extract($_REQUEST)`, allowing unauthorized access.
CVE@CVEnewDisclosure
The text announces a vulnerability (CVE-2026-28411) in WeGIA web manager involving unsafe use of `extract()` on `$_REQUEST`, but provides no PoC, exploit, or patch details.