High severity7.1NVD Advisory· Published Oct 7, 2026· Updated Oct 7, 2026
CVE-2026-46434
CVE-2026-46434
Description
wger is a free, open-source workout and fitness manager. Prior to version 2.6, a user with only the gym_trainer permission can deactivate any account in the same gym, including gym_manager and general_gym_manager accounts. The UserDeactivateView grants access to anyone holding any one of gym.manage_gym, gym.manage_gyms, or gym.gym_trainer (OR logic via WgerMultiplePermissionRequiredMixin), and performs no privilege-hierarchy check to prevent a lower-privileged role from disabling a higher-privileged one. Version 2.6 fixes the issue.
Affected products
1- Range: <2.6
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.