OVERVIEW CVE-2026-35396 is an Open Redirect vulnerability in WeGIA versions prior to 3.6.9, a web management application for charitable institutions. The flaw exists in the /WeGIA/controle/control.php endpoint where the nextPage parameter fails to validate user input when combined with specific method and class parameters, allowing attackers to redirect users to arbitrary external websites under the guise of the trusted WeGIA domain. SEVERITY The vulnerability carries a CVSS score of 6.1 (Medium) with a network-based attack vector requiring no special privileges and minimal user interaction. While the attack complexity is low and the application availability is not impacted, the vulnerability poses moderate confidentiality and integrity risks. The primary threat vector involves leveraging the trusted WeGIA domain to conduct phishing campaigns, credential harvesting, malware distribution, and social engineering attacks, with the attacker requiring only that a user click a malicious link. EXPLOITATION STATUS Currently, there is no evidence of active exploitation. The vulnerability does not appear on the Known Exploited Vulnerabilities (KEV) catalog and is listed as inactive on the Hot List, indicating minimal community or threat actor attention at this time. The extremely low EPSS score of 0.0003 further suggests negligible real-world exploitation activity. Organizations should prioritize updating to version 3.6.9 as a standard maintenance item rather than as an emergency patch.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.6.9CPE matchmatch criteria | cpe:2.3:a:wegia:wegia:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.