CVE-2026-43976High· 7.1▾ Twilightwger is a free, open-source workout and fitness manager. Prior to version 2.6, five gym management views in wger apply a flawed gym-scope guard (`gym_a != gym_b`) that silently passes when both operands are `None`. A trainer with `gym.gy…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 39.1 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
wger is a free, open-source workout and fitness manager. Prior to version 2.6, five gym management views in wger apply a flawed gym-scope guard (gym_a != gym_b) that silently passes when both operands are None. A trainer with gym.gym_trainer and gym.add_adminusernote permissions and no gym assignment (gym=None) can read private admin notes, uploaded documents, gym contracts, user configuration, and user permission data for any other unaffiliated user on the instance. The subsequent querysets filter only on the attacker-supplied member_id with no secondary gym-scoped validation, so all records are disclosed. Version 2.6 fixes the issue.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
wger <= 2.1Connected by shared product, vendor, weakness, or advisory.
CVE-2026-46437Medium· 4.8wger is a free, open-source workout and fitness manager
CVE-2026-46438Medium· 6.5wger is a free, open-source workout and fitness manager
CVE-2026-45161Medium· 5.4wger is a free, open-source workout and fitness manager
CVE-2026-46434High· 7.1wger is a free, open-source workout and fitness manager
CVE-2026-86257Medium· 5.4wger before 2.6 fails to sanitize first_name and last_name fields in the gym member TSV export endpoint, allowing any gym member to inject spreadsheet formulas
CVE-2026-86256Medium· 5.4wger before 2.6 (affected versions <= 2.5.0) contains an open redirect vulnerability in the trainer_login view (wger/core/views/user.py)