CVE-2026-43976
Deferred Deferred - Pending Action

Stored Admin Note Disclosure in wger Fitness Manager

Vulnerability report for CVE-2026-43976, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: GitHub, Inc.

Description

wger is a free, open-source workout and fitness manager. Prior to version 2.6, five gym management views in wger apply a flawed gym-scope guard (`gym_a != gym_b`) that silently passes when both operands are `None`. A trainer with `gym.gym_trainer` and `gym.add_adminusernote` permissions and no gym assignment (`gym=None`) can read private admin notes, uploaded documents, gym contracts, user configuration, and user permission data for **any other unaffiliated user** on the instance. The subsequent querysets filter only on the attacker-supplied `member_id` with no secondary gym-scoped validation, so all records are disclosed. Version 2.6 fixes the issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wger-project wger < 2.6

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-43976 is a flaw in wger gym management software versions 2.5.0 and earlier. It involves a broken authorization check in five views that allows a trainer with specific permissions and no gym assignment to bypass security and access sensitive data of other users. The check uses gym_a != gym_b which fails when both are None, enabling unauthorized access.

Detection Guidance

To detect this vulnerability, check if your wger instance is running version 2.5.0 or earlier. Inspect the five affected gym management views for the flawed gym-scope guard (`gym_a != gym_b`). Verify if trainers with `gym.gym_trainer` and `gym.add_adminusernote` permissions and no gym assignment (`gym=None`) can access unauthorized data.

Impact Analysis

An attacker with gym.gym_trainer and gym.add_adminusernote permissions and no gym assignment could read private admin notes, view uploaded documents, access gym contracts, and modify user permissions for any other user with gym=None status. This could lead to data breaches and unauthorized changes.

Compliance Impact

This vulnerability likely violates GDPR and HIPAA due to unauthorized access to sensitive user data including admin notes, documents, contracts, and permissions. It results in confidentiality breaches which are non-compliant with these regulations.

Mitigation Strategies

Upgrade wger to version 2.6 or later immediately. Review and restrict trainer permissions to prevent unauthorized access. Audit logs for suspicious activity related to admin notes, documents, contracts, and user permissions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-43976. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart