{"id":"CVE-2026-46434","title":"wger is a free, open-source workout and fitness manager","summary":"wger is a free, open-source workout and fitness manager. Prior to version 2.6, a user with only the `gym_trainer` permission can deactivate any account in the same gym, including `gym_manager` and `general_gym_manager` accounts. The `Use…","severity":"high","cvss":7.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N","cwe":["CWE-269"],"vendor":"wger-project","product":"wger","affected":["wger < 2.6"],"published":"2026-10-07","updated":"2026-10-07","sourceUpdated":"2026-10-07T15:17:20.877","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-46434","references":[{"url":"https://github.com/wger-project/wger/releases/tag/2.6","label":"security-advisories@github.com"},{"url":"https://github.com/wger-project/wger/security/advisories/GHSA-x249-cx55-2h87","label":"security-advisories@github.com"},{"url":"https://github.com/wger-project/wger/security/advisories/GHSA-x249-cx55-2h87","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://github.com/advisories/GHSA-x249-cx55-2h87"}],"tags":["nvd","cve.org","exploit-available","ghsa","pip"],"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"no","technicalImpact":"partial","timestamp":"2026-10-07T14:35:19.227767Z"},"aliases":["GHSA-x249-cx55-2h87"],"ecosystem":"pip","ingestedAt":"2026-10-07T14:33:21.954Z","slug":"CVE-2026-46434","body":"## Overview\n\nwger is a free, open-source workout and fitness manager. Prior to version 2.6, a user with only the `gym_trainer` permission can deactivate any account in the same gym, including `gym_manager` and `general_gym_manager` accounts. The `UserDeactivateView` grants access to anyone holding any one of `gym.manage_gym`, `gym.manage_gyms`, or `gym.gym_trainer` (OR logic via `WgerMultiplePermissionRequiredMixin`), and performs no privilege-hierarchy check to prevent a lower-privileged role from disabling a higher-privileged one. Version 2.6 fixes the issue.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-46434)\n\nAffected packages:\n\n- `wger <= 2.1`\n\nSource: https://github.com/advisories/GHSA-x249-cx55-2h87","depth":"midnight","depthScore":51,"depthScoreParts":{"impact":39.1,"likelihood":0,"exploitation":12,"ransomware":0},"changes":[{"seq":217558,"id":"CVE-2026-46434","ts":1791387470560,"field":"exploit_available","old":"false","new":"true"}]}