Arbitrary Workout Log Injection in wger Fitness Manager
CVE-2026-46438
6.5MEDIUM
What is CVE-2026-46438?
The wger Fitness Manager, an open-source application for tracking workouts, is susceptible to an arbitrary workout log injection vulnerability. Authenticated attackers can exploit this flaw by using another user's slot_entry ID in a specific API request, effectively manipulating the workout logs of the targeted user. The lack of proper ownership verification allows the attacker to insert data that gets seamlessly integrated into the victim's progress tracking. This can lead to inaccurate workout metrics and undermine the integrity of the fitness data generated for the affected user. A patch addressing this issue was released in version 2.6.
Affected Version(s)
wger < 2.6
