PT-2026-107516 · Wger · Wger

CVE-2026-46438

·

Published

2026-10-07

·

Updated

2026-10-07

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions wger versions prior to 2.6
Description An authenticated attacker can inject arbitrary workout log entries into another user's SlotEntry by providing the victim's slot entry ID in a POST /api/v2/workoutlog/ request. This occurs because the slot entry foreign key is omitted from the ownership verification performed by the WorkoutLogViewSet.get owner objects() function, allowing the server to persist cross-user references.
Furthermore, the SlotEntry.get config data() function retrieves associated logs using self.workoutlog set.all() without applying a user filter. Consequently, the injected data is included in the victim's progressive-overload calculations, which can corrupt auto-generated weight and repetition targets. Progressive-overload is a training method where the weight or number of repetitions is gradually increased to improve fitness.
Recommendations Update to version 2.6. As a temporary mitigation, restrict access to the POST /api/v2/workoutlog/ endpoint or avoid using the slot entry parameter until the update is applied.

Exploit

Fix

IDOR

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-46438
GHSA-RJPF-7PF5-Q54X

Affected Products

Wger