← All Advisories

CVE-2026-54670

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-54670

Key Details

CVECVE-2026-54670
CVSS Score / Version9.1 (Critical) / CVSS v3.1
Updated2026-09-23
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is none.
Affected productsLabRedesCefetRJ WeGIA
Classified asCWE-22 (Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'))

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LabRedesCefetRJWeGIA
SubsystemsGeneral OT
SectorsMultiple

What to Know

WeGIA is a web manager for charitable institutions. Prior to 3.8.5, the contribution request dispatcher in web/html/contribuicao/controller/control.php accepts attacker-controlled nomeClasse and metodo values without a complete controller and method allowlist, exempts sensitive ContribuicaoLogController operations from authentication, and constructs a controller include path without canonical directory containment. An unauthenticated remote attacker can invoke getContribuicoesLogJSON, sincronizarStatus, registrarFaturas, and other sensitive methods to disclose contribution and donation records or trigger financial workflow operations. A traversal-shaped nomeClasse value can also cause require_once to include an accessible PHP or configuration file outside the intended controller directory, exposing source code, credentials, or other sensitive local data. This issue is fixed in version 3.8.5. (NVD)

What to Do

Monitor LabRedesCefetRJ's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-54670
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-54670