Description
WeGIA is a web manager for charitable institutions. Prior to 3.8.5, WeGIA maps InternoControle to an empty resource array in web/controle/control.php, and verificarPermissao in web/dao/MiddlewareDAO.php treats that empty array as unconditional access for every authenticated user. The methods in web/controle/InternoControle.php, including listarUm, alterar, and excluir, accept user-controlled id or idInterno values without verifying ownership, allowing a low-privileged user to read, modify, or delete another person's records and expose personal, identity, address, medical, and family information. The advisory notes that a self-referencing load bug can crash this controller in the reported revision, but the empty-resource authorization pattern and affected methods remain the vulnerability under review. This issue is fixed in version 3.8.5.
Published: 2026-09-17
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Authorization bypass enabling unauthorized data manipulation
Action: Apply Patch
AI Analysis

Impact

WeGIA maps the InternoControle module to an empty resource array before version 3.8.5, and the permission verifier treats that array as granting unconditional access to any authenticated user. Consequently, methods such as listarUm, alterar, and excluir accept user supplied identifiers without checking record ownership, enabling a low‑privileged user to read, modify, or delete another individual's personal, identity, address, medical, and family information.

Affected Systems

This vulnerability affects the WeGIA web management platform developed by LabRedesCefetRJ. All deployed instances running any release prior to version 3.8.5 are susceptible; the issue was fixed in the 3.8.5 release and later versions.

Risk and Exploitability

The flaw carries a CVSS score of 8.8, indicating high severity. The EPSS score is reported as less than 1 %, suggesting a low probability of exploitation at the time of analysis, and it is not listed in the CISA KEV catalog. Exploitation requires an authenticated session; a low‑privileged user can trigger the affected endpoints to gain unauthorized data disclosure and modification. Because the flaw relies on empty‑resource authorization, there is no requirement for special network‑level access beyond normal login credentials.

Generated by OpenCVE AI on September 19, 2026 at 01:55 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade WeGIA to version 3.8.5 or later, which addresses the empty‑resource authorization issue.
  • If a patch cannot be applied immediately, deny access to InternoControle endpoints for non‑admin users via web server configuration or application‑level role checks.
  • Review and enforce ownership verification for database operations that accept user‑supplied identifiers, and monitor logs for anomalous access to InternoControle actions.

Generated by OpenCVE AI on September 19, 2026 at 01:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Labredescefetrj
Labredescefetrj wegia
Vendors & Products Labredescefetrj
Labredescefetrj wegia

Thu, 17 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description WeGIA is a web manager for charitable institutions. Prior to 3.8.5, WeGIA maps InternoControle to an empty resource array in web/controle/control.php, and verificarPermissao in web/dao/MiddlewareDAO.php treats that empty array as unconditional access for every authenticated user. The methods in web/controle/InternoControle.php, including listarUm, alterar, and excluir, accept user-controlled id or idInterno values without verifying ownership, allowing a low-privileged user to read, modify, or delete another person's records and expose personal, identity, address, medical, and family information. The advisory notes that a self-referencing load bug can crash this controller in the reported revision, but the empty-resource authorization pattern and affected methods remain the vulnerability under review. This issue is fixed in version 3.8.5.
Title WeGIA: Authorization Bypass via Empty Resource Array in InternoControle
Weaknesses CWE-639
CWE-862
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Labredescefetrj Wegia
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-18T13:09:54.841Z

Reserved: 2026-06-15T22:53:58.560Z

Link: CVE-2026-54671

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-17T22:17:03.150

Modified: 2026-09-18T13:18:33.920

Link: CVE-2026-54671

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T02:00:13Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key

  • CWE-862

    Missing Authorization