{"id":"CVE-2026-43976","title":"wger is a free, open-source workout and fitness manager","summary":"wger is a free, open-source workout and fitness manager. Prior to version 2.6, five gym management views in wger apply a flawed gym-scope guard (`gym_a != gym_b`) that silently passes when both operands are `None`. A trainer with `gym.gy…","severity":"high","cvss":7.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N","cwe":["CWE-863"],"vendor":"wger","product":"wger","affected":["wger <= 2.1"],"published":"2026-10-07","updated":"2026-10-07","sourceUpdated":"2026-10-07T14:46:03.387","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-43976","references":[{"url":"https://github.com/wger-project/wger/releases/tag/2.6","label":"security-advisories@github.com"},{"url":"https://github.com/wger-project/wger/security/advisories/GHSA-c72h-82w6-rqfp","label":"security-advisories@github.com"},{"url":"https://github.com/advisories/GHSA-c72h-82w6-rqfp"}],"tags":["nvd","ghsa","pip","cve.org"],"aliases":["GHSA-c72h-82w6-rqfp"],"ecosystem":"pip","ingestedAt":"2026-10-07T14:33:21.953Z","slug":"CVE-2026-43976","body":"## Overview\n\nwger is a free, open-source workout and fitness manager. Prior to version 2.6, five gym management views in wger apply a flawed gym-scope guard (`gym_a != gym_b`) that silently passes when both operands are `None`. A trainer with `gym.gym_trainer` and `gym.add_adminusernote` permissions and no gym assignment (`gym=None`) can read private admin notes, uploaded documents, gym contracts, user configuration, and user permission data for **any other unaffiliated user** on the instance. The subsequent querysets filter only on the attacker-supplied `member_id` with no secondary gym-scoped validation, so all records are disclosed. Version 2.6 fixes the issue.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-43976)\n\nAffected packages:\n\n- `wger <= 2.1`\n\nSource: https://github.com/advisories/GHSA-c72h-82w6-rqfp","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":39.1,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}