VYPR
High severity7.1NVD Advisory· Published Oct 7, 2026· Updated Oct 7, 2026

CVE-2026-46434

CVE-2026-46434

Description

wger is a free, open-source workout and fitness manager. Prior to version 2.6, a user with only the gym_trainer permission can deactivate any account in the same gym, including gym_manager and general_gym_manager accounts. The UserDeactivateView grants access to anyone holding any one of gym.manage_gym, gym.manage_gyms, or gym.gym_trainer (OR logic via WgerMultiplePermissionRequiredMixin), and performs no privilege-hierarchy check to prevent a lower-privileged role from disabling a higher-privileged one. Version 2.6 fixes the issue.

Affected products

1

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.