Junglewise Threat Intelligence

CVE-2026-76634: WeGIA insecure direct object reference in employee profile

CVE-2026-76634 · Severity: medium · CVSS 6.5 · Published 2026-08-20

Technologies: LabRedesCefetRJ WeGIA. Vendors: LabRedesCefetRJ.

Executive brief

WeGIA is an employee management system used to maintain personnel records. An authenticated attacker can bypass access controls in the employee profile page to view confidential data belonging to any other employee, including names, tax ID numbers (CPF), addresses, contact information, and administrative status—potentially affecting hundreds of employees.

Technical details

The vulnerability is an insecure direct object reference (IDOR) in profile_funcionario.php caused by the unsafe use of extract($_REQUEST) at line 28. This function overwrites the session-derived $id_pessoa variable with any value submitted in the HTTP request, allowing an authenticated attacker to enumerate and access arbitrary employee profiles. The vulnerable code first retrieves the user's own ID from the session, then immediately accepts and uses an attacker-supplied id_pessoa parameter for all subsequent database queries (lines 29–135). An authenticated user can simply append &id_pessoa=N to the URL, iterating through employee IDs to retrieve PII and system metadata. The vulnerability is fixed in version 3.9.2 and later by removing the dangerous extract() call and properly validating access before rendering profile data.

Affected products

  • LabRedesCefetRJ WeGIA before 3.9.2

Timeline

  • 2026-07-20: disclosed: GitHub Security Advisory GHSA-jqh5-66qr-85qv published
  • 2026-08-20: disclosed: CVE-2026-76634 published on NVD
  • 2026-07-20: patched: Fix released in version 3.9.2

References

Related threats