CVE-2026-28409 | WeGIA Vulnerable to Remote Code Execution (RCE) via OS Command Injection
Exp
WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, a critical Remote Code Execution (RCE) vulnerability exists in the WeGIA application's database restoration functionality. An attacker with administrative access (which can be obtained via the previously reported Authentication Bypass) can execute arbitrary OS commands on the server by uploading a backup file with a specifically crafted filename. Version 3.6.5 fixes the issue.
Conclusion & alert: CVE-2026-28409 is rated High Exploit Risk (87.5/100): CVSS Critical severity, with medium exploitation likelihood (EPSS 3.31%).Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). EPSS rose +2.09% over the last day, indicating growing attacker interest.Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
Public exploit references (Exploit-DB) for CVE-2026-28409
Exploit prediction scoring system (EPSS) score for CVE-2026-28409
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).