---
id: CVE-2026-82544
title: A flaw has been found in wger-project wger up to 2.6.0-alpha2
summary: >-
  A flaw has been found in wger-project wger up to 2.6.0-alpha2. This issue
  affects the function reset_user_password of the file wger/gym/views/gym.py of
  the component Password Reset. Executing a manipulation can lead to cross-site
  request…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'
cwe:
  - CWE-352
  - CWE-862
published: '2026-08-30'
updated: '2026-08-30'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-82544'
references:
  - url: 'https://github.com/wger-project/wger/'
    label: cna@vuldb.com
  - url: >-
      https://github.com/wger-project/wger/commit/3c6ce4b7f3eeafeb35318c6c4e82b1a3fd28b314
    label: cna@vuldb.com
  - url: 'https://github.com/wger-project/wger/issues/2380'
    label: cna@vuldb.com
  - url: 'https://github.com/wger-project/wger/pull/2415'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-82544'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/891417'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/397061'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/397061/cti'
    label: cna@vuldb.com
tags:
  - nvd
ingestedAt: '2026-08-30T23:59:27.923Z'
epss: 0.00241
epssPercentile: 0.1351
---

## Overview

A flaw has been found in wger-project wger up to 2.6.0-alpha2. This issue affects the function reset_user_password of the file wger/gym/views/gym.py of the component Password Reset. Executing a manipulation can lead to cross-site request forgery. It is possible to launch the attack remotely. This patch is called 3c6ce4b7f3eeafeb35318c6c4e82b1a3fd28b314. It is advisable to implement a patch to correct this issue.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
