Privilege Escalation Vulnerability in wger Workout Manager by wger Project
CVE-2026-43978
8.1HIGH
What is CVE-2026-43978?
In wger, a fitness and workout management software, an exploit allows gym trainers to elevate their privileges to that of higher-resourced accounts, such as gym managers. This flaw, which affects versions before 2.6, arises when trainers manipulate their access through the trainer-login endpoint. By initially logging in as a regular user, they set a session flag that inadvertently bypasses permission checks on future login calls. Consequently, this grants them unauthorized access to sensitive functionalities, allowing full control over the gym's administration, including accessing member data and modifying contracts. The issue has been remedied in version 2.6 of the wger application.
Affected Version(s)
wger < 2.6
