Incomplete Authorization Bypass in wger Project by wger Project
CVE-2026-86254

6.1MEDIUM

Key Information:

Status
Vendor
CVE Published:
6 September 2026

What is CVE-2026-86254?

The wger project has a notable vulnerability involving incomplete authorization checks within its codebase. Specifically, in the file user.py, certain views incorrectly perform gym-scope checks using raw integer comparisons. This flaw enables gym staff members with gym=None access to manipulate user accounts indiscriminately. Attackers possessing gym.manage_gym permissions can exploit this vulnerability to delete user accounts, deactivate them, or undo previously defensive deactivations. This misconfiguration creates a serious security concern where unauthorized actions can be executed against user accounts.

Affected Version(s)

wger 0

References

CVSS V4

Score:
6.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

HiyokoSauna37
.