Junglewise Threat Intelligence

CVE-2026-76633: WeGIA authorization bypass in password change

CVE-2026-76633 · Severity: high · CVSS 8.1 · Published 2026-08-20

Technologies: LabRedesCefetRJ WeGIA. Vendors: LabRedesCefetRJ.

Executive brief

WeGIA is a web-based human resources and account management system used by educational institutions. This vulnerability allows any logged-in user to permanently change their account password without knowing the current password, converting temporary session hijacking (via phishing, XSS, or shared devices) into permanent account takeover. An attacker with brief unauthorized access can lock out the legitimate owner and assume full control of the account.

Technical details

WeGIA versions before 3.9.2 contain an authorization bypass in the password change flow caused by two design flaws. First, the alterarSenha method in FuncionarioControle.php is unconditionally excluded from permission checks in controle/control.php (line 84), allowing any authenticated user to invoke it. Second, the method can be routed via the redir parameter to call verificarSenhaConfig() instead of verificarSenha(), which skips old password verification and only validates password complexity and confirmation. An attacker with any valid session (temporary or compromised) can POST to /controle/control.php with metodo=alterarSenha, redir=alterar_senha.php, and a new password to permanently change the target account's credentials without authentication. The fix is available in version 3.9.2 and later.

Affected products

  • LabRedesCefetRJ WeGIA before 3.9.2

Timeline

  • 2026-07-20: disclosed
  • 2026-07-20: patched: version 3.9.2 released

References

Related threats