Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-35396

24
FAUCET Score

OVERVIEW CVE-2026-35396 is an Open Redirect vulnerability in WeGIA versions prior to 3.6.9, a web management application for charitable institutions. The flaw exists in the /WeGIA/controle/control.php endpoint where the nextPage parameter fails to validate user input when combined with specific method and class parameters, allowing attackers to redirect users to arbitrary external websites under the guise of the trusted WeGIA domain. SEVERITY The vulnerability carries a CVSS score of 6.1 (Medium) with a network-based attack vector requiring no special privileges and minimal user interaction. While the attack complexity is low and the application availability is not impacted, the vulnerability poses moderate confidentiality and integrity risks. The primary threat vector involves leveraging the trusted WeGIA domain to conduct phishing campaigns, credential harvesting, malware distribution, and social engineering attacks, with the attacker requiring only that a user click a malicious link. EXPLOITATION STATUS Currently, there is no evidence of active exploitation. The vulnerability does not appear on the Known Exploited Vulnerabilities (KEV) catalog and is listed as inactive on the Hot List, indicating minimal community or threat actor attention at this time. The extremely low EPSS score of 0.0003 further suggests negligible real-world exploitation activity. Organizations should prioritize updating to version 3.6.9 as a standard maintenance item rather than as an emergency patch.

Impacted Technologies

VendorProductVersion(s)CPE
< 3.6.9CPE matchmatch criteria
cpe:2.3:a:wegia:wegia:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

5.1MEDIUM

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
ACTIVE
VS Confidentiality
LOW
VS Integrity
LOW
VS Availability
NONE
SS Confidentiality
LOW
SS Integrity
LOW
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.22%
Probability of exploitation in next 30 days
EPSS Percentile
13.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0022 is in the 13th percentile among its peer group of 26,236 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (1)

github_advisoryvendor investigatingvia nvd_reference
View patch

References

github.com / LabRedesCefetRJ/WeGIA/security/advisories/GHSA-4qxc-5j5f-4gp5
ExploitVendor Advisory