CVE-2026-46434
Deferred Deferred - Pending Action

Privilege Escalation in wger Workout Manager

Vulnerability report for CVE-2026-46434, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: GitHub, Inc.

Description

wger is a free, open-source workout and fitness manager. Prior to version 2.6, a user with only the `gym_trainer` permission can deactivate any account in the same gym, including `gym_manager` and `general_gym_manager` accounts. The `UserDeactivateView` grants access to anyone holding any one of `gym.manage_gym`, `gym.manage_gyms`, or `gym.gym_trainer` (OR logic via `WgerMultiplePermissionRequiredMixin`), and performs no privilege-hierarchy check to prevent a lower-privileged role from disabling a higher-privileged one. Version 2.6 fixes the issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wger-project wger < 2.6

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-269 The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-46434 is a privilege escalation vulnerability in the wger workout manager software affecting versions before 2.6. It allows a user with only the gym_trainer permission to deactivate any account within the same gym, including higher-privileged accounts like gym_manager and general_gym_manager.

Detection Guidance

Check if any accounts with gym_trainer permission have deactivated higher-privileged accounts by reviewing user activity logs and account statuses. Look for unusual deactivation events in the wger application logs or database.

Impact Analysis

This vulnerability can lead to gym management lockout and denial of service. Deactivated managers cannot log in or perform administrative tasks until manually reactivated by a superadmin. Attackers could exploit this by visiting a specific URL to deactivate higher-privileged accounts.

Mitigation Strategies

Upgrade wger to version 2.6 or later to apply the privilege hierarchy checks. Review and reactivate any deactivated accounts, especially higher-privileged ones. Restrict gym_trainer role assignments to trusted users only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-46434. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart