Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 20 Aug 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | WeGIA before 3.9.2 contains an insecure direct object reference vulnerability in the employee profile page that allows authenticated attackers to access arbitrary employee records by injecting an id_pessoa parameter through a request extraction function that overwrites the session-derived identifier. Attackers can enumerate all user identifiers to retrieve full profile data for any employee account, including name, CPF, address, contact details, and administrative flags. | |
| Title | WeGIA < 3.9.2 Insecure Direct Object Reference via profile_funcionario.php | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-20T14:49:43.435Z
Reserved: 2026-08-19T14:53:58.574Z
Link: CVE-2026-76634
No data.
Status : Received
Published: 2026-08-20T14:17:59.837
Modified: 2026-08-20T14:17:59.837
Link: CVE-2026-76634
No data.
OpenCVE Enrichment
No data.