Arbitrary Workout Log Injection in wger Fitness Manager
CVE-2026-46438

6.5MEDIUM

Key Information:

Status
Vendor
CVE Published:
7 October 2026

What is CVE-2026-46438?

The wger Fitness Manager, an open-source application for tracking workouts, is susceptible to an arbitrary workout log injection vulnerability. Authenticated attackers can exploit this flaw by using another user's slot_entry ID in a specific API request, effectively manipulating the workout logs of the targeted user. The lack of proper ownership verification allows the attacker to insert data that gets seamlessly integrated into the victim's progress tracking. This can lead to inaccurate workout metrics and undermine the integrity of the fitness data generated for the affected user. A patch addressing this issue was released in version 2.6.

Affected Version(s)

wger < 2.6

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.