PT-2026-107516 · Wger · Wger
CVE-2026-46438
·
Published
2026-10-07
·
Updated
2026-10-07
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
wger versions prior to 2.6
Description
An authenticated attacker can inject arbitrary workout log entries into another user's
SlotEntry by providing the victim's slot entry ID in a POST /api/v2/workoutlog/ request. This occurs because the slot entry foreign key is omitted from the ownership verification performed by the WorkoutLogViewSet.get owner objects() function, allowing the server to persist cross-user references.Furthermore, the
SlotEntry.get config data() function retrieves associated logs using self.workoutlog set.all() without applying a user filter. Consequently, the injected data is included in the victim's progressive-overload calculations, which can corrupt auto-generated weight and repetition targets. Progressive-overload is a training method where the weight or number of repetitions is gradually increased to improve fitness.Recommendations
Update to version 2.6.
As a temporary mitigation, restrict access to the
POST /api/v2/workoutlog/ endpoint or avoid using the slot entry parameter until the update is applied.Exploit
Fix
IDOR
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wger