CVE-2026-28411
published 2026-02-27CVE-2026-28411: WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, an unsafe use of the `extract()` function on the `$_REQUEST` superglobal allows an…
PriorityP278critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EXPLOIT
EPSS
2.91%
86.5th percentile
WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, an unsafe use of the `extract()` function on the `$_REQUEST` superglobal allows an unauthenticated attacker to overwrite local variables in multiple PHP scripts. This vulnerability can be leveraged to completely bypass authentication checks, allowing unauthorized access to administrative and protected areas of the WeGIA application. Version 3.6.5 fixes the issue.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| labredescefetrj | wegia | < 3.6.5 | 3.6.5 |
| wegia | wegia | < 3.6.5 | 3.6.5 |
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No advisories linked to this vulnerability.
No detection rules found.
Nuclei
WeGIA < 3.6.5 - Unauthenticated Authentication Bypass via extract()
nuclei·CVSS 9.8
CVE-2026-28411 [CRITICAL] WeGIA < 3.6.5 - Unauthenticated Authentication Bypass via extract()
WeGIA < 3.6.5 - Unauthenticated Authentication Bypass via extract()
WeGIA < 3.6.5 contains an authentication bypass caused by unsafe use of extract() on $_REQUEST, letting unauthenticated attackers bypass authentication and access protected areas, exploit requires no authentication.
Template:
id: CVE-2026-28411
info:
name: WeGIA < 3.6.5 - Unauthenticated Authentication Bypass via extract()
author: str4k3r,0x_Akoko
severity: critical
description: |
WeGIA < 3.6.5 contains an authentication bypass caused by unsafe use of extract() on $_REQUEST, letting unauthenticated attackers bypass authentication and access protected areas, exploit requires no authentication.
impact: |
Unauthenticated attackers can bypass authentication and gain unauthorized administrative access.
remediation: |
Upgrad
No writeups or analysis indexed.
2026-02-27
Published