CVE-2026-86274

Summary

A security vulnerability has been detected in projeto-siga siga up to 11.0.2.10/11.0.2.13/11.1.1. This affects the function ExAutenticacaoController.autenticar of the file sigaex/src/main/java/br/gov/jfrj/siga/vraptor/ExAutenticacaoController.java of the component Authentication Flow. Such manipulation of the argument cod/jwt leads to missing authorization. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Affected Software

VendorProductVersion RangeStatus
projeto-sigasiga11.0.2.0affected
projeto-sigasiga11.0.2.1affected
projeto-sigasiga11.0.2.2affected
projeto-sigasiga11.0.2.3affected
projeto-sigasiga11.0.2.4affected
projeto-sigasiga11.0.2.5affected
projeto-sigasiga11.0.2.6affected
projeto-sigasiga11.0.2.7affected
projeto-sigasiga11.0.2.8affected
projeto-sigasiga11.0.2.9affected
projeto-sigasiga11.0.2.10affected
projeto-sigasiga11.0.2.11affected
projeto-sigasiga11.0.2.12affected
projeto-sigasiga11.0.2.13affected
projeto-sigasiga11.1.0affected
projeto-sigasiga11.1.1affected

Weaknesses

  • CWE-862: Missing Authorization
  • CWE-863: Incorrect Authorization

References