CVE-2026-43976: high-severity vulnerability in wger-project wger
wger: cross-tenant admin notes/contracts leak via gym=None bypass (5 views)
Published
18Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.1
exploitation probability
—
observed exploitation
nono source reports it
wger is a free, open-source workout and fitness manager. Prior to version 2.6, five gym management views in wger apply a flawed gym-scope guard (`gym_a != gym_b`) that silently passes when both operands are `None`. A trainer with `gym.gym_trainer` and `gym.add_adminusernote` permissions and no gym assignment (`gym=None`) can read private admin notes, uploaded documents, gym contracts, user configuration, and user permission data for **any other unaffiliated user** on the instance. The subsequent querysets filter only on the attacker-supplied `member_id` with no secondary gym-scoped validation, so all records are disclosed. Version 2.6 fixes the issue.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Affected products
wger-project · wgerRelated CVEs — wger-project wger
In the same product, most dangerous first.
CVE-2026-43948CRITICALwger: cross-tenant password reset and plaintext disclosure via gym=None bypassEPSS 0.4%CVE-2026-86255HIGHwger before 2.5 Uncontrolled Resource Consumption via date_sequenceEPSS 0.4%CVE-2026-40474HIGHwger has Broken Access Control in the Global Gym Configuration Update EndpointEPSS 0.4%CVE-2026-43977HIGHwger IDOR: Authenticated Users Can Read Others' Private Workout Session Data via Template Routine APIEPSS 0.4%CVE-2026-43978HIGHwger: Privilege escalation via trainer-login session chaining allows gym trainers to impersonate gym managersEPSS 0.4%CVE-2026-86254MEDIUMwger Incomplete Authorization Fix Cross-Tenant Account DeletionEPSS 0.4%