CVE-2026-31894: WeGIA affected by arbitrary file read via symlink in backup restore
WeGIA is a web manager for charitable institutions. In 3.6.5, The patched loadBackupDB() extracts tar.gz archives to a temporary directory using PHP's PharData class, then uses glob() and filegetcontents() to read SQL files from the extracted contents. Neither the extraction nor the file reading validates whether archive members are symbolic links. This vulnerability is fixed in 3.6.6.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-31894?
CVE-2026-31894 has a high severity due to the potential for arbitrary file read via symlink.
How do I fix CVE-2026-31894?
To fix CVE-2026-31894, upgrade WeGIA to version 3.6.6 or later.
Who is affected by CVE-2026-31894?
Users of WeGIA versions prior to 3.6.6 are affected by CVE-2026-31894.
What are the risks associated with CVE-2026-31894?
The risks include unauthorized access to sensitive files on the server due to symlink exploitation.
What versions of WeGIA are vulnerable to CVE-2026-31894?
WeGIA versions up to 3.6.5 are vulnerable to CVE-2026-31894.