PT-2026-44042 · Wegia · Wegia

·

CVE-2026-45027

·

Published

2026-05-27

·

Updated

2026-05-27

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions WeGIA versions prior to 3.7.3
Description When a user logs in via the 'html/login.php' endpoint, the system hashes the submitted password using the PHP hash() function with the SHA-256 algorithm and no salt. The password change flow in 'controle/FuncionarioControle.php' follows the same pattern. Because SHA-256 is a general-purpose cryptographic hash designed for speed rather than password storage, the absence of a salt means identical passwords produce identical digests. This allows the hash database to be compromised using a precomputed rainbow table lookup, which is a technique used to reverse cryptographic hash functions using large precomputed tables of hashes.
Recommendations Update to version 3.7.3.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-45027
GHSA-HCGV-VMQ6-J6QG

Affected Products

Wegia