OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-54670

CRITICAL · CVSS 9.1 EPSS 0.69% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-17 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The contribution request dispatcher in WeGIA versions prior to 3.8.5 is vulnerable to unauthenticated remote attacks due to improper handling of user-controlled input, allowing attackers to invoke sensitive methods and access confidential contribution and donation records. Additionally, the lack of a complete allowlist for controller paths can lead to directory traversal attacks, potentially exposing sensitive files and credentials. Organizations using WeGIA should prioritize patching to version 3.8.5 to mitigate these critical vulnerabilities.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-54670
Severity
CRITICAL
CVSS
9.1
EPSS
0.69%

Original NVD Description

WeGIA is a web manager for charitable institutions. Prior to 3.8.5, the contribution request dispatcher in web/html/contribuicao/controller/control.php accepts attacker-controlled nomeClasse and metodo values without a complete controller and method allowlist, exempts sensitive ContribuicaoLogController operations from authentication, and constructs a controller include path without canonical directory containment. An unauthenticated remote attacker can invoke getContribuicoesLogJSON, sincronizarStatus, registrarFaturas, and other sensitive methods to disclose contribution and donation records or trigger financial workflow operations. A traversal-shaped nomeClasse value can also cause require_once to include an accessible PHP or configuration file outside the intended controller directory, exposing source code, credentials, or other sensitive local data. This issue is fixed in version 3.8.5.