Description
A security vulnerability has been detected in projeto-siga siga up to 11.0.2.10/11.0.2.13/11.1.1. This affects the function ExAutenticacaoController.autenticar of the file sigaex/src/main/java/br/gov/jfrj/siga/vraptor/ExAutenticacaoController.java of the component Authentication Flow. Such manipulation of the argument cod/jwt leads to missing authorization. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-09-07
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a missing authorization flaw in the ExAutenticacaoController.autenticar function. By manipulating the cod/jwt argument, an attacker can bypass normal access controls and obtain unauthorized privileges. The weakness is classified as CWE-862 (Missing Authorization) and CWE-863 (Failed or Insufficient Authorization). The effect is that sensitive data or protected operations can be accessed by unauthenticated or improperly authorized users.

Affected Systems

The affected product is projeto‑siga Siga software. Versions up to 11.0.2.10, 11.0.2.13, and 11.1.1 are vulnerable. Any deployment of essas versões without a subsequent update is at risk.

Risk and Exploitability

The CVSS base score of 6.9 indicates a moderate severity. The vulnerability can be leveraged remotely by crafting a request that manipulates the cod/jwt parameter, though the EPSS is not reported. It is not currently listed in the CISA KEV catalog. If unpatched, the risk is that an attacker could gain unauthorized access to protected resources, potentially leading to data exposure or unauthorized actions.

Generated by OpenCVE AI on September 7, 2026 at 06:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Projeto‑Siga Siga release that addresses the missing authorization issue; if a newer release is unavailable, upgrade to a version that removes the flaw.
  • If a patch cannot be applied immediately, block or restrict access to the ExAutenticacaoController endpoint for untrusted clients using firewall rules or IP whitelisting.
  • Implement or reinforce authorization checks to ensure that payloads containing a cod/jwt parameter are validated against the requesting user’s permissions before granting access.

Generated by OpenCVE AI on September 7, 2026 at 06:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 07 Sep 2026 05:30:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in projeto-siga siga up to 11.0.2.10/11.0.2.13/11.1.1. This affects the function ExAutenticacaoController.autenticar of the file sigaex/src/main/java/br/gov/jfrj/siga/vraptor/ExAutenticacaoController.java of the component Authentication Flow. Such manipulation of the argument cod/jwt leads to missing authorization. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Title projeto-siga Authentication Flow ExAutenticacaoController.java ExAutenticacaoController.autenticar authorization
First Time appeared Projeto-siga
Projeto-siga siga
Weaknesses CWE-862
CWE-863
CPEs cpe:2.3:a:projeto-siga:siga:*:*:*:*:*:*:*:*
Vendors & Products Projeto-siga
Projeto-siga siga
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:N/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Projeto-siga Siga
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-07T05:15:11.895Z

Reserved: 2026-09-06T13:16:19.380Z

Link: CVE-2026-86274

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-07T06:17:23.820

Modified: 2026-09-07T06:17:23.820

Link: CVE-2026-86274

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-07T06:30:17Z

Weaknesses