Junglewise Threat Intelligence

CVE-2026-86274: projeto-siga SIGA authentication bypass in document access

CVE-2026-86274 · Severity: medium · CVSS 5.3 · Published 2026-09-07

Executive brief

SIGA is a Brazilian government document management system used to control access to restricted files. A vulnerability in its public document authentication flow allows anyone with a document reference number to bypass access-code validation by submitting any non-empty code value, obtaining a server-signed JWT token that grants unauthorized access to restricted document content regardless of the actual access permissions.

Technical details

The vulnerability is an authorization bypass (CWE-862, CWE-287) in the ExAutenticacaoController.autenticar method of the public document authentication flow. The root cause is that the controller validates only whether the access-code (cod) parameter is non-empty before issuing a JWT, without checking whether the supplied code matches the document's external-access token. Although the client-side page performs the actual token validation, the issued JWT is already signed by the server and trusted by the subsequent /public/app/arquivoAutenticado_stream endpoint, which verifies only the JWT signature without revalidating document authorization. An unauthenticated attacker with knowledge of a document reference number can supply any non-empty cod value, receive a valid server-signed JWT, and use it to retrieve the restricted document content. The fix requires validating cod with the full ExPodeVisualizarExternamente validator before JWT issuance and binding explicit authorization claims to the JWT.

Affected products

  • projeto-siga SIGA up to 11.0.2.10, 11.0.2.13, 11.1.1

Timeline

  • 2026-07-25: disclosed: Vulnerability reported via GitHub issue #2493
  • 2026-09-07: advisory: CVE-2026-86274 published on NVD

References

Related threats