WeGIA <= 3.6.4 - Remote Code Execution
CVE-2026-28409
Verified
Description
WeGIA <= 3.6.5 contains a remote code execution caused by improper validation of backup file names in the database restoration functionality, letting attackers with administrative access execute arbitrary OS commands
Severity
Critical
CVSS Score
10
Exploit Probability
4%
Affected Product
wegia
Published Date
April 17, 2026
Template Author
0x_akoko
CVE-2026-28409.yaml
10.0Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVE ID:
cve-2026-28409
CWE ID:
cwe-78
Remediation Steps
Upgrade to version 3.6.5 or later.