PT-2026-107514 · Wger · Wger
CVE-2026-46434
·
Published
2026-10-07
·
Updated
2026-10-07
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
wger versions prior to 2.6
Description
A privilege management issue exists where a user with the
gym trainer permission can deactivate any account within the same gym, including those with higher privileges such as gym manager and general gym manager. This occurs because the UserDeactivateView and UserActivateView grant access to any user holding any one of the required permissions without performing a privilege-hierarchy check to ensure a lower-privileged role cannot disable a higher-privileged one.Technical details include:
- API Endpoints:
/en/user/{manager user id}/deactivate - Vulnerable Parameters or Variables:
pk(used to identify the target user) - Function Names:
WgerMultiplePermissionRequiredMixin.has permission()andUserDeactivateView.dispatch()
Recommendations
Update to version 2.6.
As a temporary workaround, restrict the assignment of the
gym trainer role to trusted users only to minimize the risk of unauthorized account deactivation.Exploit
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wger