CVE-2026-86274 | projeto-siga up to 11.0.2.10/11.0.2.13/11.1.1 Authentication Flow ExAutenticacaoController.java ExAutenticacaoController.autenticar cod/jwt authorization (Issue 2493)
A vulnerability classified as problematic was found in projeto-siga siga up to 11.0.2.10/11.0.2.13/11.1.1. This affects the function ExAutenticacaoController.autenticar of the file sigaex/src/main/java/br/gov/jfrj/siga/vraptor/ExAutenticacaoController.java of the component Authentication Flow. Such manipulation of the argument cod/jwt leads to missing authorization.
This vulnerability is traded as CVE-2026-86274. The attack may be launched remotely. Furthermore, there is an exploit available.
The project was informed of the problem early through an issue report but has not responded yet.