Junglewise Threat Intelligence

CVE-2026-54767: WeGIA unauthenticated database truncation in member endpoint

CVE-2026-54767 · Severity: critical · CVSS 9.1 · Published 2026-09-17

Technologies: LabRedesCefetRJ WeGIA. Vendors: LabRedesCefetRJ.

Executive brief

WeGIA is a web-based system for managing member and donor records at charitable organizations. Prior to version 3.8.5, an unauthenticated attacker who obtains a hardcoded security key can directly delete all member, contributor, and address records from the system without any login credentials. This permanently destroys critical organizational data and requires manual recovery from backups.

Technical details

The vulnerability is an authentication bypass combined with SQL injection or direct database manipulation in the deletar_socios.php controller endpoint. The endpoint accepts a GET parameter (chave) that is validated only against a hardcoded value present in the public GitHub repository, rather than server-side session authentication or application-level authorization controls. An attacker with knowledge of this hardcoded chave value can invoke TRUNCATE TABLE operations on the endereco, pessoafisica, pessoajuridica, and socio tables. The attack is network-accessible, requires no authentication or user interaction, and succeeds if the affected tables exist and the database account has truncation privileges. The vulnerability was fixed in version 3.8.5 by removing the vulnerable file entirely.

Affected products

  • LabRedesCefetRJ WeGIA prior to 3.8.5

Timeline

  • 2026-09-17: disclosed
  • 2026-05-28: patched: Fix merged via PR #1689

References

Related threats