PatchSiren cyber security CVE debrief
CVE-2026-35399 LabRedesCefetRJ CVE debrief
CVE-2026-35399 is a stored XSS vulnerability in WeGIA, a Web manager for charitable institutions, prior to version 3.6.9. An attacker can inject malicious scripts through a backup filename, potentially leading to unauthorized execution of malicious code in the victim's browser. This vulnerability could compromise session data or execute actions on behalf of the user. The vulnerability is fixed in version 3.6.9. Users should review the official advisory for specific guidance on affected versions and upgrade paths.
- Vendor
- LabRedesCefetRJ
- Product
- WeGIA
- CVSS
- HIGH 8.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-06
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-04-06
- Advisory updated
- 2026-07-24
Who should care
Users of WeGIA versions prior to 3.6.9 should apply the patch to prevent exploitation of this vulnerability. This includes administrators and security teams responsible for maintaining WeGIA instances, as well as operators who use the Web manager for charitable institutions. Reviewing the official advisory and CVE record can help determine specific exposure and required actions.
Technical summary
A stored XSS vulnerability exists in WeGIA, a Web manager for charitable institutions, prior to version 3.6.9. This vulnerability allows an attacker to inject malicious scripts through a backup filename, which could lead to unauthorized execution of malicious code in the victim's browser, compromising session data or executing actions on behalf of the user. The vulnerability is fixed in version 3.6.9. There is no evidence of public exploitation or additional technical details available beyond the CVE record and NVD entry.
Defensive priority
High priority should be given to applying the patch for CVE-2026-35399, as it addresses a high-severity vulnerability that could lead to unauthorized code execution. Defenders should focus on patching exposed systems and reviewing existing backups for potential malicious scripts.
Recommended defensive actions
- Apply the patch to upgrade WeGIA to version 3.6.9 or later
- Review and update any existing backups to ensure they do not contain malicious scripts
- Monitor for suspicious activity on WeGIA instances
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record was published on 2026-04-06T21:16:21.897Z and has not been modified since. The NVD entry is currently Analyzed. There is no additional information available about the vulnerability beyond what is provided in the CVE record and NVD entry. Defenders should verify the affected scope and severity based on the official advisory.
Official resources
-
CVE-2026-35399 CVE record
CVE.org
-
CVE-2026-35399 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Exploit, Vendor Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-06T21:16:21.897Z and has not been modified since.