CVE-2026-46434 PUBLISHED

wger: Trainer Privilege Escalation - Improper Privilege Management

Assigner: GitHub_M
Reserved: 13.05.2026 Published: 07.10.2026 Updated: 07.10.2026

wger is a free, open-source workout and fitness manager. Prior to version 2.6, a user with only the gym_trainer permission can deactivate any account in the same gym, including gym_manager and general_gym_manager accounts. The UserDeactivateView grants access to anyone holding any one of gym.manage_gym, gym.manage_gyms, or gym.gym_trainer (OR logic via WgerMultiplePermissionRequiredMixin), and performs no privilege-hierarchy check to prevent a lower-privileged role from disabling a higher-privileged one. Version 2.6 fixes the issue.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
CVSS Score: 7.1

Product Status

Vendor wger-project
Product wger
Versions
  • Version < 2.6 is affected

References

Problem Types

  • CWE-269: Improper Privilege Management CWE