PT-2026-86526 · Wger · Wger

·

CVE-2026-86257

·

Published

2026-05-06

·

Updated

2026-09-06

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions wger versions prior to 2.6
Description The application fails to sanitize the first name and last name fields within the gym member TSV export endpoint. This allows a gym member to perform CSV Injection by inserting spreadsheet formulas, such as =HYPERLINK, into these fields. When an administrator opens the exported file using software like Excel or LibreOffice Calc, these formulas can be executed to exfiltrate administrative data or run arbitrary code.
Recommendations Update wger to version 2.6 or later. As a temporary mitigation, restrict the use of the gym member TSV export endpoint until the update is applied.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-86257
GHSA-XQ9M-HMP9-FW87

Affected Products

Wger