References https://avd.aliyun.com/detail?id=AVD-2026-28409 https://cve.imfht.com/detail/CVE-2026-28409 https://www.gm7.org/archives/48232 https://ddpoc.com/DVB-2026-11138.html https://nvd.nist.gov/vuln/detail/CVE-2026-28409 https://github.com/LabRedesCefetRJ/WeGIA/security/advisories/GHSA-5m5g-q2vv-rv3r https://mondoo.com/vulnerability-intelligence/vulnerability/CVE-2026-28409 https://access.redhat.com/security/cve/cve-2026-28409
Related VulnerabilitiesPoCCVE-2026-28411: WeGIA < 3.6.5 - Unauthenticated Authentication Bypass via extract()PoCCVE-2026-28409: WeGIA <= 3.6.4 - Remote Code ExecutionPoCCVE-2025-55169: WeGIA - Directory Traversal