THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-76633 (HIGH 8.1) — WeGIA before 3.9.2 contains an authorization bypass vulnerability in the password change flow that allows any authenticated user to change their account password without providing existing credentials by exploiting the unconditional exclusion of the alterarSenha method from permi

[NVD] CVE-2026-76633 (HIGH 8.1) — WeGIA before 3.9.2 contains an authorization bypass vulnerability in the password change flow that allows any authenticated user to change their account password without providing existing credentials by exploiting the unconditional exclusion of the alterarSenha method from permi

mednvdPublished 2026-08-20

CVE-2026-76633 CVSS: 8.1 HIGH Published: 2026-08-20T14:17:59.680

WeGIA before 3.9.2 contains an authorization bypass vulnerability in the password change flow that allows any authenticated user to change their account password without providing existing credentials by exploiting the unconditional exclusion of the alterarSenha method from permission checks in controle/control.php. Attackers can ma

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-76633