CVE-2026-54767: WeGIA: Hardcoded Secret Key Backdoor — Mass Data Destruction via deletar_socios.php

Published Sep 17, 2026
·
Updated

WeGIA is a web manager for charitable institutions. Prior to 3.8.5, web/html/socio/sistema/controller/deletarsocios.php exposes an unauthenticated GET endpoint whose chave parameter is checked only against a hardcoded chavecorreta value embedded in the public source repository. A remote attacker who obtains that value can reach the endpoint's TRUNCATE TABLE operations for the endereco, pessoafisica, pessoajuridica, and socio tables without an administrative session or application authorization, permanently destroying member and contributor records. The attack requires the affected tables to exist and the web process database account to possess truncation privileges. This issue is fixed in version 3.8.5.

Affected Software

1 affected component
WeGIA<3.8.5

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade WeGIA (weGIA) to a version that resolves this vulnerability.

    Fixed in 3.8.5
  2. Compensating control

    Ensure the web process database account does not have TRUNCATE TABLE privileges for the endereco, pessoafisica, pessoajuridica, and socio tables (the attack requires truncation privileges on these tables).

  3. Compensating control

    If feasible, remove direct external access to the unauthenticated endpoint deletar_socios.php (web/html/socio/sistema/controller/deletar_socios.php) so attackers cannot invoke the TRUNCATE TABLE functionality via GET without an administrative session or application authorization.

Event History

Sep 17, 2026
CVE Published
via MITRE·09:56 PM
Data Sourced
via MITRE·09:56 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

Any remote attacker who can obtain the hardcoded chave_correta value can invoke the unauthenticated GET endpoint. No administrative session or other application authorization is required.

2

What conditions must exist for the destructive operation to succeed?

The endereco, pessoafisica, pessoajuridica, and socio tables must exist, and the web process database account must have permission to truncate them. If successful, the affected member and contributor records are permanently destroyed.

3

Are default or publicly exposed deployments at particular risk?

Deployments are at risk if they run a version prior to 3.8.5 and expose the affected endpoint, because the required secret value is embedded in the public source repository. The endpoint is reachable through an unauthenticated GET request.

4

What should be done if patching cannot happen immediately?

Restrict access to the affected endpoint and remove truncation privileges from the web process database account where operationally possible. These steps can prevent the endpoint from performing the destructive database operations until version 3.8.5 can be deployed.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203