CVE-2026-54670: WeGIA: Unauthenticated Auth Bypass + Local File Inclusion

Published Sep 17, 2026
·
Updated

WeGIA is a web manager for charitable institutions. Prior to 3.8.5, the contribution request dispatcher in web/html/contribuicao/controller/control.php accepts attacker-controlled nomeClasse and metodo values without a complete controller and method allowlist, exempts sensitive ContribuicaoLogController operations from authentication, and constructs a controller include path without canonical directory containment. An unauthenticated remote attacker can invoke getContribuicoesLogJSON, sincronizarStatus, registrarFaturas, and other sensitive methods to disclose contribution and donation records or trigger financial workflow operations. A traversal-shaped nomeClasse value can also cause requireonce to include an accessible PHP or configuration file outside the intended controller directory, exposing source code, credentials, or other sensitive local data. This issue is fixed in version 3.8.5.

Affected Software

1 affected component
WeGIA WeGIA web manager<3.8.5

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade WeGIA to a version that resolves this vulnerability.

    Fixed in 3.8.5

Event History

Sep 17, 2026
CVE Published
via MITRE·09:54 PM
Data Sourced
via MITRE·09:54 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are affected?

WeGIA deployments running versions before 3.8.5 are affected. The issue is reachable remotely without authentication through the contribution request dispatcher.

2

What can an unauthenticated attacker do?

An attacker can call sensitive contribution-related methods, including getContribuicoesLogJSON, sincronizarStatus, and registrarFaturas, to disclose contribution or donation records or trigger financial workflow operations. They may also use a traversal-shaped nomeClasse value to include accessible PHP or configuration files outside the intended controller directory.

3

What is required for exploitation?

No credentials or user interaction are required, and the attack complexity is low. Exploitation requires network access to the affected WeGIA web application.

4

What should be done if patching cannot happen immediately?

The provided data identifies version 3.8.5 as the fix. It does not provide a documented workaround or compensating control for unpatched deployments.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203