CVE-2026-46434: fallo de gravedad alta en wger-project wger
wger: Trainer Privilege Escalation - Improper Privilege Management
Publicada el
18Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 7.1
probabilidad de explotación
—
explotación observada
noninguna fuente lo reporta
wger is a free, open-source workout and fitness manager. Prior to version 2.6, a user with only the `gym_trainer` permission can deactivate any account in the same gym, including `gym_manager` and `general_gym_manager` accounts. The `UserDeactivateView` grants access to anyone holding any one of `gym.manage_gym`, `gym.manage_gyms`, or `gym.gym_trainer` (OR logic via `WgerMultiplePermissionRequiredMixin`), and performs no privilege-hierarchy check to prevent a lower-privileged role from disabling a higher-privileged one. Version 2.6 fixes the issue.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
Productos afectados
wger-project · wgerCVEs relacionadas — wger-project wger
En el mismo producto, de las más peligrosas a las menos.
CVE-2026-43948CRITICALwger: cross-tenant password reset and plaintext disclosure via gym=None bypassEPSS 0.4%CVE-2026-86255HIGHwger before 2.5 Uncontrolled Resource Consumption via date_sequenceEPSS 0.4%CVE-2026-40474HIGHwger has Broken Access Control in the Global Gym Configuration Update EndpointEPSS 0.4%CVE-2026-43977HIGHwger IDOR: Authenticated Users Can Read Others' Private Workout Session Data via Template Routine APIEPSS 0.4%CVE-2026-43978HIGHwger: Privilege escalation via trainer-login session chaining allows gym trainers to impersonate gym managersEPSS 0.4%CVE-2026-86254MEDIUMwger Incomplete Authorization Fix Cross-Tenant Account DeletionEPSS 0.4%