← Vulnerability feed

Vulnerability record · CVE-2026-28409 · published 27 February 2026

CVE-2026-28409: Wegia os command injection vulnerability

Wegia · Wegia

WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, a critical Remote Code Execution (RCE) vulnerability exists in the WeGIA application's database restoration functionality. An attacker with administrative access (which can be obtained via the previously reported Authentication Bypass) can execute arbitrary OS commands on the server by uploading a backup file with a specifically crafted filename. Version 3.6.5 fixes the issue.

7.2 CVSS 3.1 High EPSS 3.8% · top 10.2% CWE-78 · OS command injection
7.2CVSS 3.1 base score
3.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, a critical Remote Code Execution (RCE) vulnerability exists in the WeGIA application's database restoration functionality. An attacker with administrative access (which can be obtained via the previously reported Authentication Bypass) can execute arbitrary OS commands on the server by uploading a backup file with a specifically crafted filename. Version 3.6.5 fixes the issue.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-28409 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2025-55169Wegia path traversal vulnerabilityWeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. Prior to version 3.4.8, a path traversal vul…EPSS 1.6%10.0CVE-2025-53823Wegia sql injection vulnerabilityWeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. Versions prior to 3.4.5 have a SQL Injection…EPSS 0.47%10.0CVE-2025-53091Wegia sql injection vulnerabilityWeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Time-Based Blind SQL Injection vulnerabili…EPSS 0.50%10.0CVE-2025-46828Wegia sql injection vulnerabilityWeGIA is a web manager for charitable institutions. An unauthenticated SQL Injection vulnerability was identified in versions up to and including 3.3…EPSS 0.55%10.0CVE-2025-30367Wegia sql injection vulnerabilityWeGIA is a Web manager for charitable institutions. A SQL Injection vulnerability was identified in versions prior to 3.2.6 in the nextPage parameter…EPSS 0.50%10.0CVE-2025-30364Wegia sql injection vulnerabilityWeGIA is a Web manager for charitable institutions. A SQL Injection vulnerability was identified in versions prior to 3.2.8 in the endpoint /WeGIA/ht…EPSS 0.65%10.0CVE-2025-27140Wegia os command injection vulnerabilityWeGIA is a Web manager for charitable institutions. An OS Command Injection vulnerability was discovered in versions prior to 3.2.15 of the WeGIA app…EPSS 2.9%10.0CVE-2025-26616Wegia path traversal vulnerabilityWeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A Path Traversal vulnerability was discovered in the …EPSS 0.68%

Source: NIST National Vulnerability Database (record CVE-2026-28409), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.