{"id":"CVE-2026-82544","title":"A flaw has been found in wger-project wger up to 2.6.0-alpha2","summary":"A flaw has been found in wger-project wger up to 2.6.0-alpha2. This issue affects the function reset_user_password of the file wger/gym/views/gym.py of the component Password Reset. Executing a manipulation can lead to cross-site request…","severity":"medium","cvss":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N","cwe":["CWE-352","CWE-862"],"published":"2026-08-30","updated":"2026-08-30","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-82544","references":[{"url":"https://github.com/wger-project/wger/","label":"cna@vuldb.com"},{"url":"https://github.com/wger-project/wger/commit/3c6ce4b7f3eeafeb35318c6c4e82b1a3fd28b314","label":"cna@vuldb.com"},{"url":"https://github.com/wger-project/wger/issues/2380","label":"cna@vuldb.com"},{"url":"https://github.com/wger-project/wger/pull/2415","label":"cna@vuldb.com"},{"url":"https://vuldb.com/cve/CVE-2026-82544","label":"cna@vuldb.com"},{"url":"https://vuldb.com/submit/891417","label":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/397061","label":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/397061/cti","label":"cna@vuldb.com"}],"tags":["nvd"],"ingestedAt":"2026-08-30T23:59:27.923Z","epss":0.00241,"epssPercentile":0.1351,"slug":"CVE-2026-82544","body":"## Overview\n\nA flaw has been found in wger-project wger up to 2.6.0-alpha2. This issue affects the function reset_user_password of the file wger/gym/views/gym.py of the component Password Reset. Executing a manipulation can lead to cross-site request forgery. It is possible to launch the attack remotely. This patch is called 3c6ce4b7f3eeafeb35318c6c4e82b1a3fd28b314. It is advisable to implement a patch to correct this issue.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":24,"depthScoreParts":{"impact":23.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}