User Account Deactivation Flaw in Wger Workout Manager by Wger Project
CVE-2026-46434

7.1HIGH

Key Information:

Status
Vendor
CVE Published:
7 October 2026

What is CVE-2026-46434?

The Wger Workout Manager, prior to its release of version 2.6, contains a significant vulnerability where users with the gym_trainer role are able to deactivate any user account within the same gym, including higher-privileged roles such as gym_manager and general_gym_manager. The flaw arises from the inadequate privilege-checking functionality in the UserDeactivateView, which allows users holding certain permissions to disable accounts without proper hierarchy validation. This oversight presents a serious security risk, allowing lower-privileged users to disrupt access to gym management for more privileged accounts.

Affected Version(s)

wger < 2.6

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.