CVE-2026-46434High· 7.1▾ MidnightPoC availablewger is a free, open-source workout and fitness manager. Prior to version 2.6, a user with only the `gym_trainer` permission can deactivate any account in the same gym, including `gym_manager` and `general_gym_manager` accounts. The `Use…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 39.1 · likelihood 0 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Exploit / PoC code exists
wger is a free, open-source workout and fitness manager. Prior to version 2.6, a user with only the gym_trainer permission can deactivate any account in the same gym, including gym_manager and general_gym_manager accounts. The UserDeactivateView grants access to anyone holding any one of gym.manage_gym, gym.manage_gyms, or gym.gym_trainer (OR logic via WgerMultiplePermissionRequiredMixin), and performs no privilege-hierarchy check to prevent a lower-privileged role from disabling a higher-privileged one. Version 2.6 fixes the issue.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
wger <= 2.1Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-46437Medium· 4.8wger is a free, open-source workout and fitness manager
CVE-2026-46438Medium· 6.5wger is a free, open-source workout and fitness manager
CVE-2026-45161Medium· 5.4wger is a free, open-source workout and fitness manager
CVE-2026-43976High· 7.1wger is a free, open-source workout and fitness manager
CVE-2026-86257Medium· 5.4wger before 2.6 fails to sanitize first_name and last_name fields in the gym member TSV export endpoint, allowing any gym member to inject spreadsheet formulas
CVE-2026-86256Medium· 5.4wger before 2.6 (affected versions <= 2.5.0) contains an open redirect vulnerability in the trainer_login view (wger/core/views/user.py)