PT-2026-22412 · Wegia · Wegia

Hunterxsirago1

·

Published

2026-02-27

·

Updated

2026-04-21

·

CVE-2026-28409

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WeGIA versions prior to 3.6.5
Description WeGIA is a web manager for charitable institutions. A critical Remote Code Execution (RCE) issue exists in the application’s database restoration functionality. An attacker with administrative access can execute arbitrary OS commands on the server by uploading a specifically crafted backup file. The vulnerability is triggered through a filename manipulation within the database restoration process.
Recommendations Versions prior to 3.6.5 should be updated to version 3.6.5 or later.

Exploit

Fix

RCE

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-28409
GHSA-5M5G-Q2VV-RV3R

Affected Products

Wegia