User Account Deactivation Flaw in Wger Workout Manager by Wger Project
CVE-2026-46434
7.1HIGH
What is CVE-2026-46434?
The Wger Workout Manager, prior to its release of version 2.6, contains a significant vulnerability where users with the gym_trainer role are able to deactivate any user account within the same gym, including higher-privileged roles such as gym_manager and general_gym_manager. The flaw arises from the inadequate privilege-checking functionality in the UserDeactivateView, which allows users holding certain permissions to disable accounts without proper hierarchy validation. This oversight presents a serious security risk, allowing lower-privileged users to disrupt access to gym management for more privileged accounts.
Affected Version(s)
wger < 2.6
