CVE-2026-45027: WeGIA: Use of Weak Password Hashing Algorithm (SHA-256, no salt) in html/login.php
WeGIA is a web manager for charitable institutions. In versions prior to 3.7.3, when a user logs in, html/login.php hashes the submitted password using PHP's hash() function with the SHA-256 algorithm and no salt before comparing it to the stored value. The password change flow in controle/FuncionarioControle.php follows the same pattern. SHA-256 is a general-purpose cryptographic hash built for speed, not password storage. Without a salt, identical passwords produce identical digests, making the entire hash database vulnerable to a single precomputed rainbow table lookup. This vulnerability is fixed in 3.7.3.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-45027?
The severity of CVE-2026-45027 is medium with a score of 5.9.
How do I fix CVE-2026-45027?
To fix CVE-2026-45027, upgrade to WeGIA version 3.7.3 or later, which eliminates the use of weak password hashing.
What is the impact of CVE-2026-45027 on user passwords?
CVE-2026-45027 allows attackers to potentially crack user passwords due to the use of SHA-256 without salt.
Is CVE-2026-45027 an authenticated attack vector?
Yes, CVE-2026-45027 can be exploited by authenticated users because it affects the login process.
What feature of WeGIA is affected by CVE-2026-45027?
CVE-2026-45027 affects the password hashing method used in the login process in html/login.php.