PT-2026-83562 · Wger · Wger

·

CVE-2026-82544

·

Published

2026-08-30

·

Updated

2026-08-31

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X
Name of the Vulnerable Software and Affected Versions wger-project wger versions prior to 2.6.0-alpha2
Description A flaw in the Password Reset component allows for remote cross-site request forgery (CSRF), a type of attack that forces an authenticated user to execute unwanted actions on a web application. The issue resides in the reset user password() function within the wger/gym/views/gym.py file.
Recommendations Apply patch 3c6ce4b7f3eeafeb35318c6c4e82b1a3fd28b314 to versions prior to 2.6.0-alpha2. As a temporary mitigation, restrict access to the reset user password() function until the patch is applied.

Exploit

Fix

CSRF

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82544

Affected Products

Wger