Incomplete Authorization Bypass in wger Project by wger Project
CVE-2026-86254
6.1MEDIUM
What is CVE-2026-86254?
The wger project has a notable vulnerability involving incomplete authorization checks within its codebase. Specifically, in the file user.py, certain views incorrectly perform gym-scope checks using raw integer comparisons. This flaw enables gym staff members with gym=None access to manipulate user accounts indiscriminately. Attackers possessing gym.manage_gym permissions can exploit this vulnerability to delete user accounts, deactivate them, or undo previously defensive deactivations. This misconfiguration creates a serious security concern where unauthorized actions can be executed against user accounts.
Affected Version(s)
wger 0
