PT-2026-107514 · Wger · Wger

CVE-2026-46434

·

Published

2026-10-07

·

Updated

2026-10-07

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
Name of the Vulnerable Software and Affected Versions wger versions prior to 2.6
Description A privilege management issue exists where a user with the gym trainer permission can deactivate any account within the same gym, including those with higher privileges such as gym manager and general gym manager. This occurs because the UserDeactivateView and UserActivateView grant access to any user holding any one of the required permissions without performing a privilege-hierarchy check to ensure a lower-privileged role cannot disable a higher-privileged one.
Technical details include:
  • API Endpoints: /en/user/{manager user id}/deactivate
  • Vulnerable Parameters or Variables: pk (used to identify the target user)
  • Function Names: WgerMultiplePermissionRequiredMixin.has permission() and UserDeactivateView.dispatch()
Recommendations Update to version 2.6. As a temporary workaround, restrict the assignment of the gym trainer role to trusted users only to minimize the risk of unauthorized account deactivation.

Exploit

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-46434
GHSA-X249-CX55-2H87

Affected Products

Wger