Open Redirect Vulnerability in wger by Wger Project
CVE-2026-86256
5.1MEDIUM
What is CVE-2026-86256?
The wger application prior to version 2.6 has a vulnerability in the trainer_login view that allows an attacker to exploit the 'next' GET parameter. This can lead to unauthorized redirection of authenticated trainers to an external domain controlled by the attacker. The vulnerability arises because the application fails to validate the provided redirect URL, which can facilitate phishing attempts and expose sensitive information via the HTTP Referer header.
Affected Version(s)
wger 0 < 2.6
wger 2.6
