Skip to main content
CRITICAL

CVE-2026-28411

WeGIA Vulnerable to Authentication Bypass via `extract($_REQUEST)`

CVSS v3

9.8

CRITICAL

EPSS Score

2.9 %

exploit probability, as of 2026-09-25

CISA KEV

No

known exploited

Exploitation

poc

SSVC status

Description

WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, an unsafe use of the `extract()` function on the `$_REQUEST` superglobal allows an unauthenticated attacker to overwrite local variables in multiple PHP scripts. This vulnerability can be leveraged to completely bypass authentication checks, allowing unauthorized access to administrative and protected areas of the WeGIA application. Version 3.6.5 fixes the issue.

Technical details

Published
2026-02-27
Last Modified
2026-03-03

Frequently asked questions

What is CVE-2026-28411?

WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, an unsafe use of the `extract()` function on the `$_REQUEST` superglobal allows an unauthenticated attacker to overwrite local variables in multiple PHP scripts. This vulnerability can be leveraged to completely bypass authentication checks, allowing unauthorized access to administrative and protected areas of the WeGIA application. Version 3.6.5 fixes the issue.

Is CVE-2026-28411 actively exploited?

A proof-of-concept exploit exists for CVE-2026-28411, but active exploitation has not been confirmed at this time.

What is the CVSS score for CVE-2026-28411?

CVE-2026-28411 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2026-28411 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key