External risk intelligence

WeGIA Contribution Request Dispatcher Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-54670

WeGIA is a web-based management application designed for charitable institutions. As a web application that handles contributions and donor records, it is typically deployed as an internet-facing service to allow users to interact with the platform, making it a likely target for remote, network-based access.

Path Traversal

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability exists in the WeGIA web manager, a system used by charitable institutions. This issue allows unauthenticated remote attackers to access sensitive donation records and trigger financial operations, or potentially expose source code and credentials by manipulating file inclusion.

  • Unauthenticated access to donation data and financial operations.
  • Matters due to potential exposure of sensitive financial and system data.
  • Confirm relevance and ascertain organizational exposure.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can access the WeGIA web manager over the network and target the contribution request dispatcher. By sending crafted requests that bypass authentication and manipulate controller include paths, an attacker can either view sensitive donation data or execute financial operations, and potentially disclose local files.

  • No authentication required.
  • Trigger sensitive controller methods.
  • Disclose data or execute actions.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated remote attacker to access sensitive contribution and donation records or trigger financial operations. It may also enable the disclosure of source code, credentials, or other local data by including unintended files.

  • Contribution and donation data at risk.
  • Unauthenticated remote access via web requests.
  • Disclosure of sensitive records or credentials.

Operational Fix

Recommended remediation, mitigation, and detection steps

Application owners and infrastructure teams should coordinate to address this vulnerability in the WeGIA web manager. The immediate priority is to identify all instances of the affected software, determine their exposure and criticality, and assign an owner for remediation. Planning for updates or other mitigation strategies should follow, prioritizing systems with the highest risk.

  • Identify application owners and inventory instances.
  • Verify external accessibility and business criticality.
  • Plan and execute updates or compensating controls.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the WeGIA software?

WeGIA is a web-based management platform built specifically for charitable institutions. It functions as a central dashboard to help these organizations track donations, manage contribution requests, and oversee internal financial workflows.

How does CVE-2026-54670 compromise security?

This vulnerability involves improper authentication and path traversal weaknesses. It allows attackers to bypass security checks and manipulate the system's request dispatcher, enabling unauthorized access to sensitive data or the ability to trigger restricted financial functions.

Do I need to be authenticated to trigger this bug?

No. The vulnerability exists because the software fails to verify user credentials for sensitive operations. An attacker can initiate these malicious actions remotely without needing a login account, though standard administrative operations remain unaffected.

Why is this CVE urgent for internet-facing systems?

According to Halo Surface Signal, WeGIA is typically deployed as an internet-facing service to facilitate donor interaction. Because the vulnerability is reachable over the network without authentication, systems exposed to the public internet are at the highest risk.

How do I secure my WeGIA installation?

The primary step is to upgrade your WeGIA instance to version 3.8.5 or later, which includes the necessary security patches. You should also audit your current deployment to confirm which systems are internet-facing and ensure they are updated immediately.

References