Open Redirect Vulnerability in wger by Wger Project
CVE-2026-86256

5.1MEDIUM

Key Information:

Status
Vendor
CVE Published:
6 September 2026

What is CVE-2026-86256?

The wger application prior to version 2.6 has a vulnerability in the trainer_login view that allows an attacker to exploit the 'next' GET parameter. This can lead to unauthorized redirection of authenticated trainers to an external domain controlled by the attacker. The vulnerability arises because the application fails to validate the provided redirect URL, which can facilitate phishing attempts and expose sensitive information via the HTTP Referer header.

Affected Version(s)

wger 0 < 2.6

wger 2.6

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

whatisproblem
.