/Vulnerability Library

WeGIA < 3.6.5 - Unauthenticated Authentication Bypass via extract()

CVE-2026-28411
Verified

Description

WeGIA < 3.6.5 contains an authentication bypass caused by unsafe use of extract() on $_REQUEST, letting unauthenticated attackers bypass authentication and access protected areas, exploit requires no authentication.

Severity

Critical

CVSS Score

9.8

Exploit Probability

3%

Affected Product

wegia

Published Date

September 2, 2026

Template Author

str4k3r, 0x_akoko

CVE-2026-28411.yaml
9.8Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2026-28411
CWE ID:
cwe-287

References

https://github.com/LabRedesCefetRJ/WeGIA/security/advisories/GHSA-jg7w-3wg7-4vhhhttps://nvd.nist.gov/vuln/detail/CVE-2026-28411

Remediation Steps

Upgrade to version 3.6.5 or later.