CVE-2026-43976 PUBLISHED

wger: cross-tenant admin notes/contracts leak via gym=None bypass (5 views)

Assigner: GitHub_M
Reserved: 04.05.2026 Published: 07.10.2026 Updated: 07.10.2026

wger is a free, open-source workout and fitness manager. Prior to version 2.6, five gym management views in wger apply a flawed gym-scope guard (gym_a != gym_b) that silently passes when both operands are None. A trainer with gym.gym_trainer and gym.add_adminusernote permissions and no gym assignment (gym=None) can read private admin notes, uploaded documents, gym contracts, user configuration, and user permission data for any other unaffiliated user on the instance. The subsequent querysets filter only on the attacker-supplied member_id with no secondary gym-scoped validation, so all records are disclosed. Version 2.6 fixes the issue.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
CVSS Score: 7.1

Product Status

Vendor wger-project
Product wger
Versions
  • Version < 2.6 is affected

References

Problem Types

  • CWE-863: Incorrect Authorization CWE