CRITICAL 9.1 CVE-2026-54670 Published 17 Sept 2026

WeGIA Web Manager Unauthenticated Access Vulnerability

Worried this affects your website?

WeGIA, a web manager for charitable institutions, is affected. Prior to version 3.8.5, the contribution request dispatcher in web/html/contribuicao/controller/control.php accepts attacker-controlled 'nomeClasse' and 'metodo' values without proper validation, allowing unauthenticated remote attackers to invoke sensitive methods and expose contribution records or trigger financial workflow operations.

Additionally, a traversal-shaped 'nomeClasse' value can cause require_once to include an accessible PHP or configuration file outside the intended controller directory, exposing sensitive data.

  • Versions affected: Prior to 3.8.5
  • Impact: Unauthenticated access to sensitive data and operations

Reference: CVE-2026-54670 on NVD

← Back to Security News