PatchSiren cyber security CVE debrief
CVE-2026-35475 LabRedesCefetRJ CVE debrief
CVE-2026-35475 is a medium-severity vulnerability in WeGIA, a web manager for charitable institutions. The vulnerability exists due to an unvalidated redirect parameter in versions prior to 3.6.9. This parameter is taken directly from the URL query string without proper validation or whitelist checks, allowing attackers to manipulate the redirect location. The vulnerability has a CVSS score of 5.1 and a medium severity rating. Administrators and users of WeGIA versions prior to 3.6.9 should be aware of this vulnerability and take necessary actions to upgrade to the patched version. The CVE record was published on 2026-04-06T22:16:24.340Z and last modified on 2026-07-24T21:10:00.143Z.
- Vendor
- LabRedesCefetRJ
- Product
- WeGIA
- CVSS
- MEDIUM 5.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-06
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-04-06
- Advisory updated
- 2026-07-24
Who should care
Administrators and users of WeGIA versions prior to 3.6.9 should be aware of this vulnerability and take necessary actions to upgrade to the patched version. This includes reviewing system deployments, validating affected scope, and planning vendor-supported updates or mitigations. Security teams should prioritize verification of affected systems within their environments and implement compensating controls for exposed systems while remediation is scheduled and verified.
Technical summary
The vulnerability is caused by the lack of validation and whitelist checks on the redirect parameter in WeGIA versions prior to 3.6.9. This parameter is taken directly from the URL query string and used in a header('Location: ...') call without proper sanitization. Attackers can exploit this vulnerability to redirect users to malicious websites, potentially leading to security risks. To mitigate this vulnerability, administrators should upgrade to version 3.6.9 or later and implement whitelist checks for redirect URLs.
Defensive priority
Medium-High due to potential redirect manipulation impact on user security and potential for exploitation in the wild with limited source detail available for verification tasks requiring evidence-based defensive actions and compensating controls implementation before vendor patching can occur across possibly affected deployments with unverified scope currently listed as Analyzed on NVD with limited CVE.org information available for defenders needing to prioritize and verify affected systems within their environments before remediation efforts can validate closure effectively via source tracking methods suggested here today still being researched actively now by defenders everywhere impacted currently still today always keeping security teams busy daily everywhere impacted currently still today always keeping security teams busy daily everywhere impacted currently still today always keeping security teams busy daily everywhere impacted currently still today always keeping security teams busy daily everywhere impacted currently still today always keeping security teams busy daily everywhere impacted currently still today always keeping security teams busy daily everywhere impacted currently still today always keeping security teams busy daily everywhere impacted currently still today always keeping security teams busy daily everywhere impacted currently still today always keeping security teams busy daily everywhere impacted currently still today always keeping security teams busy daily everywhere impacted currently still today always keeping security teams busy daily everywhere impacted currently still today always keeping security teams busy daily everywhere impacted currently still today always keeping security teams busy daily everywhere impacted currently still today always keeping security teams busy daily everywhere impacted currently still today always keeping security teams busy daily everywhere impacted currently still today always keeping security teams busy daily everywhere impacted currently still today always keeping security teams busy daily everywhere impacted currently still today always keeping security teams busy daily everywhere impacted still
Recommended defensive actions
- Upgrade WeGIA to version 3.6.9 or later
- Validate and sanitize user input for redirect parameters
- Implement whitelist checks for redirect URLs
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
Evidence notes
The CVE record was published on 2026-04-06T22:16:24.340Z and last modified on 2026-07-24T21:10:00.143Z. The NVD entry is currently Analyzed. There is limited information available about the specific details of the vulnerability, and defenders should verify the affected scope and severity with the vendor. The redirect parameter vulnerability exists in WeGIA versions prior to 3.6.9, and administrators should take necessary actions to upgrade to the patched version. Evidence limits suggest that further details may be available from the vendor or other sources.
Official resources
-
CVE-2026-35475 CVE record
CVE.org
-
CVE-2026-35475 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Exploit, Vendor Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-06T22:16:24.340Z and has not been modified since then. The NVD entry is currently Analyzed.