THREAT OPS › Threat News › [NVD] CVE-2026-76633 (HIGH 8.1) — WeGIA before 3.9.2 contains an authorization bypass vulnerability in the password change flow that allows any authenticated user to change their account password without providing existing credentials by exploiting the unconditional exclusion of the alterarSenha method from permi
[NVD] CVE-2026-76633 (HIGH 8.1) — WeGIA before 3.9.2 contains an authorization bypass vulnerability in the password change flow that allows any authenticated user to change their account password without providing existing credentials by exploiting the unconditional exclusion of the alterarSenha method from permi
CVE-2026-76633 CVSS: 8.1 HIGH Published: 2026-08-20T14:17:59.680
WeGIA before 3.9.2 contains an authorization bypass vulnerability in the password change flow that allows any authenticated user to change their account password without providing existing credentials by exploiting the unconditional exclusion of the alterarSenha method from permission checks in controle/control.php. Attackers can ma
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-76633cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-76633