← Voltar à pesquisa de CVEs

CVE-2026-43978

wger

Descrição

wger is a free, open-source workout and fitness manager. In versions prior to 2.6, a gym trainer can escalate their session to any higher-privileged account (gym manager, general manager) by chaining two calls to the trainer-login endpoint. Once a trainer performs a legitimate switch into a low-privileged user, the session flag trainer.identity is set and this flag alone bypasses the permission check on all subsequent trainer-login calls. This grants full gym administration capabilities including viewing all member data, modifying contracts, managing gym configuration, and accessing other trainers- and managers- personal information. This issue has been fixed in version 2.6.

CVSS 8.1EPSS 0.213%Risco 0.83
Ver fonte
Publicação
2026-07-16 23:16:16
Versões afetadas
<2.6
Tipo
Aplicação web
Vetor
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N