Cross-Site Request Forgery Vulnerability in wger-project's Password Reset Function
CVE-2026-82544

5.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
30 August 2026

What is CVE-2026-82544?

A vulnerability has been identified in the wger Workout Manager that affects the password reset functionality located in the gym.py file. This flaw enables an attacker to manipulate requests leading to unauthorized actions, potentially compromising user accounts through cross-site request forgery (CSRF). This type of attack can be executed remotely, emphasizing the need for implementing the provided patch to safeguard against exploitation.

Affected Version(s)

wger 2.6.0-alpha2

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Galaxyn (VulDB User)
.