Description
WeGIA is a web manager for charitable institutions. Prior to 3.8.5, web/html/socio/sistema/controller/deletar_socios.php exposes an unauthenticated GET endpoint whose chave parameter is checked only against a hardcoded chave_correta value embedded in the public source repository. A remote attacker who obtains that value can reach the endpoint's TRUNCATE TABLE operations for the endereco, pessoafisica, pessoajuridica, and socio tables without an administrative session or application authorization, permanently destroying member and contributor records. The attack requires the affected tables to exist and the web process database account to possess truncation privileges. This issue is fixed in version 3.8.5.
Published: 2026-09-17
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Mass Data Destruction
Action: Immediate Patch
AI Analysis

Impact

The flaw allows a remote attacker who discovers the hard‑coded secret key in the public source to invoke a vulnerable HTTP GET endpoint, deletar_socios.php, without needing any authentication. The endpoint then executes TRUNCATE TABLE statements on the endereco, pessoafisica, pessoajuridica, and socio tables, permanently deleting all member and contributor records. The exploitation requires only that the affected tables exist and that the database account used by the web process has TRUNCATE privileges. The impact is the irreversible loss of critical organisational data.

Affected Systems

The vulnerability affects installations of the WeGIA web manager for charitable institutions from all release versions prior to 3.8.5. The vendor is LabRedesCefetRJ, and the affected component is the deletar_socios.php controller within the web/html/socio/sistema directory.

Risk and Exploitability

The CVSS score of 9.1 indicates a high severity vulnerability, and the EPSS score of less than 1% implies a low probability of exploitation in the wild. The flaw is not listed in CISA’s KEV catalog. Because the secret key is embedded in the public code repository, the likely attack vector is an unauthenticated remote HTTP request, and discovery of the key is trivial. Successful exploitation yields complete data loss without administrative access or application authorisation.

Generated by OpenCVE AI on September 19, 2026 at 01:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade WeGIA to version 3.8.5 or later, where the hard-coded key and unauthenticated endpoint have been removed.
  • Restrict the database privileges of the web application account so that it does not possess TRUNCATE rights on the endereco, pessoafisica, pessoajuridica, and socio tables.
  • Implement monitoring and firewall rules to detect and block suspicious requests to deletar_socios.php, and audit any recent deletions or data loss events.

Generated by OpenCVE AI on September 19, 2026 at 01:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Labredescefetrj
Labredescefetrj wegia
Vendors & Products Labredescefetrj
Labredescefetrj wegia

Thu, 17 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description WeGIA is a web manager for charitable institutions. Prior to 3.8.5, web/html/socio/sistema/controller/deletar_socios.php exposes an unauthenticated GET endpoint whose chave parameter is checked only against a hardcoded chave_correta value embedded in the public source repository. A remote attacker who obtains that value can reach the endpoint's TRUNCATE TABLE operations for the endereco, pessoafisica, pessoajuridica, and socio tables without an administrative session or application authorization, permanently destroying member and contributor records. The attack requires the affected tables to exist and the web process database account to possess truncation privileges. This issue is fixed in version 3.8.5.
Title WeGIA: Hardcoded Secret Key Backdoor — Mass Data Destruction via deletar_socios.php
Weaknesses CWE-306
CWE-798
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H'}


Subscriptions

Labredescefetrj Wegia
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-18T20:04:14.441Z

Reserved: 2026-06-15T23:23:57.713Z

Link: CVE-2026-54767

cve-icon Vulnrichment

Updated: 2026-09-18T20:04:09.909Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T22:17:03.470

Modified: 2026-09-18T20:17:17.253

Link: CVE-2026-54767

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T02:00:13Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function

  • CWE-798

    Use of Hard-coded Credentials