Privilege Escalation Vulnerability in wger Workout Manager by wger Project
CVE-2026-43978

8.1HIGH

Key Information:

Status
Vendor
CVE Published:
16 July 2026

What is CVE-2026-43978?

In wger, a fitness and workout management software, an exploit allows gym trainers to elevate their privileges to that of higher-resourced accounts, such as gym managers. This flaw, which affects versions before 2.6, arises when trainers manipulate their access through the trainer-login endpoint. By initially logging in as a regular user, they set a session flag that inadvertently bypasses permission checks on future login calls. Consequently, this grants them unauthorized access to sensitive functionalities, allowing full control over the gym's administration, including accessing member data and modifying contracts. The issue has been remedied in version 2.6 of the wger application.

Affected Version(s)

wger < 2.6

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.