CVE-2026-46438
Deferred Deferred - Pending Action

Authenticated Workout Log Injection in wger Fitness Manager

Vulnerability report for CVE-2026-46438, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: GitHub, Inc.

Description

wger is a free, open-source workout and fitness manager. Prior to version 2.6, an authenticated attacker can inject arbitrary workout log entries into any other user's `SlotEntry` by supplying the victim's `slot_entry` ID in a `POST /api/v2/workoutlog/` request. The `slot_entry` foreign key is not included in the ownership verification performed by `WorkoutLogViewSet.get_owner_objects()`, so the server accepts and persists the cross-user reference without error. Because `SlotEntry.get_config_data()` retrieves associated logs via `self.workoutlog_set.all()` with no user filter, the attacker's injected data is silently folded into the victim's progressive-overload calculations, corrupting their auto-generated weight and repetition targets. Version 2.6 contains a patch.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wger-project wger < 2.6

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-46438 is a vulnerability in the wger workout manager software where an authenticated attacker can inject fake workout log entries into another user's training data. The issue occurs because the system fails to verify ownership of the slot_entry foreign key, allowing attackers to link their data to a victim's account. This corrupted data then affects the victim's workout calculations.

Detection Guidance

Check wger API logs for POST requests to /api/v2/workoutlog/ with slot_entry IDs not belonging to the authenticated user. Look for entries where workout logs are linked to users without proper ownership verification.

Impact Analysis

If you use wger, an attacker could alter your workout logs, leading to incorrect weight and repetition targets. This could disrupt your fitness progress tracking and potentially cause injuries if targets are set too high. The attack requires the attacker to have a valid account and know your slot_entry ID.

Compliance Impact

This vulnerability could potentially impact compliance with data integrity requirements under GDPR and HIPAA by allowing unauthorized modification of user workout data. Attackers can inject false workout logs into another user's training records, which may corrupt progressive-overload calculations and lead to inaccurate health or fitness tracking. This could violate principles of data accuracy and integrity required by these regulations.

Mitigation Strategies

Upgrade wger to version 2.6 or later to apply the patch. If upgrading is not immediately possible, restrict API access to trusted users and monitor for unauthorized POST requests to /api/v2/workoutlog/.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-46438. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart