High severity7.1GHSA Advisory· Published Oct 7, 2026· Updated Oct 7, 2026
CVE-2026-43976
CVE-2026-43976
Description
wger is a free, open-source workout and fitness manager. Prior to version 2.6, five gym management views in wger apply a flawed gym-scope guard (gym_a != gym_b) that silently passes when both operands are None. A trainer with gym.gym_trainer and gym.add_adminusernote permissions and no gym assignment (gym=None) can read private admin notes, uploaded documents, gym contracts, user configuration, and user permission data for any other unaffiliated user on the instance. The subsequent querysets filter only on the attacker-supplied member_id with no secondary gym-scoped validation, so all records are disclosed. Version 2.6 fixes the issue.
Affected products
2<= 2.1+ 1 more
- (no CPE)range: <= 2.1
- (no CPE)
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.