peter bassill · operator
$ cve CVE-2026-28409 JSON

CVE-2026-28409

10.0
CRITICAL · CVSS 3.1 · EPSS 3.8% (pctl 90)

In your normal cycle

Critical by CVSS (10), but no sign of active exploitation.

Description

WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, a critical Remote Code Execution (RCE) vulnerability exists in the WeGIA application's database restoration functionality. An attacker with administrative access (which can be obtained via the previously reported Authentication Bypass) can execute arbitrary OS commands on the server by uploading a backup file with a specifically crafted filename. Version 3.6.5 fixes the issue.

Scoring

CVSS10.0 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS3.85% — more likely to be exploited than 90% of all CVEs
WeaknessCWE-78
On CISA KEVno
Public exploitnone known
Published2026-02-27
Last modified2026-06-17

Affected (1)

VendorProduct
wegiawegia

References

→ the Explorer  ·  watch your stack  ·  NVD