CVE-2026-46438Medium· 6.5▾ Sunlitwger is a free, open-source workout and fitness manager. Prior to version 2.6, an authenticated attacker can inject arbitrary workout log entries into any other user's `SlotEntry` by supplying the victim's `slot_entry` ID in a `POST /api…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
wger is a free, open-source workout and fitness manager. Prior to version 2.6, an authenticated attacker can inject arbitrary workout log entries into any other user's SlotEntry by supplying the victim's slot_entry ID in a POST /api/v2/workoutlog/ request. The slot_entry foreign key is not included in the ownership verification performed by WorkoutLogViewSet.get_owner_objects(), so the server accepts and persists the cross-user reference without error. Because SlotEntry.get_config_data() retrieves associated logs via self.workoutlog_set.all() with no user filter, the attacker's injected data is silently folded into the victim's progressive-overload calculations, corrupting their auto-generated weight and repetition targets. Version 2.6 contains a patch.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
wger <= 2.1Connected by shared product, vendor, weakness, or advisory.
CVE-2026-46437Medium· 4.8wger is a free, open-source workout and fitness manager
CVE-2026-45161Medium· 5.4wger is a free, open-source workout and fitness manager
CVE-2026-46434High· 7.1wger is a free, open-source workout and fitness manager
CVE-2026-43976High· 7.1wger is a free, open-source workout and fitness manager
CVE-2026-86254Medium· 6.8wger versions through master contain an incomplete authorization bypass in wger/core/views/user.py where three views retain the original gym-scope check using raw integer comparison instead of the is_same_gym() helper, allowing gym staff…
CVE-2026-86257Medium· 5.4wger before 2.6 fails to sanitize first_name and last_name fields in the gym member TSV export endpoint, allowing any gym member to inject spreadsheet formulas