PT-2026-95160 · Wegia · Wegia

·

CVE-2026-54767

·

Published

2026-09-17

·

Updated

2026-09-17

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions WeGIA versions prior to 3.8.5
Description An unauthenticated GET endpoint at 'web/html/socio/sistema/controller/deletar socios.php' validates the chave parameter against a hardcoded chave correta value found in the public source repository. A remote attacker possessing this value can bypass administrative sessions and application authorization to execute TRUNCATE TABLE operations—which permanently remove all rows from a table—on the endereco, pessoafisica, pessoajuridica, and socio tables. This action results in the permanent destruction of member and contributor records, provided the tables exist and the database account used by the web process has truncation privileges.
Recommendations Update to version 3.8.5. Restrict access to the 'web/html/socio/sistema/controller/deletar socios.php' endpoint as a temporary mitigation.

Exploit

Fix

Missing Authentication

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54767
GHSA-399W-RXHP-JH9F

Affected Products

Wegia