CVE-2026-43978: CWE-269: Improper Privilege Management in wger-project wger
wger before version 2.6 contains an improper privilege management vulnerability allowing gym trainers to escalate their session privileges to higher roles such as gym manager or general manager. This is achieved by chaining calls to the trainer-login endpoint, bypassing permission checks and granting full administrative capabilities. The issue is fixed in version 2.6.
AI Analysis
Technical Summary
The wger open-source workout and fitness manager has a privilege escalation vulnerability (CWE-269) in versions prior to 2.6. A gym trainer can exploit the trainer-login endpoint by first switching to a low-privileged user, which sets a session flag 'trainer.identity'. This flag bypasses permission checks on subsequent trainer-login calls, enabling the attacker to escalate privileges to gym manager or general manager roles. This grants unauthorized access to sensitive member data, contract modifications, gym configuration, and personal information of other trainers and managers. The vulnerability is resolved in wger version 2.6.
Potential Impact
Exploitation allows a gym trainer to gain full administrative privileges, including viewing and modifying sensitive member and contract data, managing gym configurations, and accessing personal information of other users. This compromises confidentiality and integrity of the system data but does not affect availability.
Mitigation Recommendations
Upgrade to wger version 2.6 or later, where this privilege escalation vulnerability has been fixed. No other mitigation is indicated by the vendor advisory.
CVE-2026-43978: CWE-269: Improper Privilege Management in wger-project wger
Description
wger before version 2.6 contains an improper privilege management vulnerability allowing gym trainers to escalate their session privileges to higher roles such as gym manager or general manager. This is achieved by chaining calls to the trainer-login endpoint, bypassing permission checks and granting full administrative capabilities. The issue is fixed in version 2.6.
CVSS v3.1
Score 8.1high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The wger open-source workout and fitness manager has a privilege escalation vulnerability (CWE-269) in versions prior to 2.6. A gym trainer can exploit the trainer-login endpoint by first switching to a low-privileged user, which sets a session flag 'trainer.identity'. This flag bypasses permission checks on subsequent trainer-login calls, enabling the attacker to escalate privileges to gym manager or general manager roles. This grants unauthorized access to sensitive member data, contract modifications, gym configuration, and personal information of other trainers and managers. The vulnerability is resolved in wger version 2.6.
Potential Impact
Exploitation allows a gym trainer to gain full administrative privileges, including viewing and modifying sensitive member and contract data, managing gym configurations, and accessing personal information of other users. This compromises confidentiality and integrity of the system data but does not affect availability.
Mitigation Recommendations
Upgrade to wger version 2.6 or later, where this privilege escalation vulnerability has been fixed. No other mitigation is indicated by the vendor advisory.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-05-04T20:24:31.916Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a595c2d68715ace43d0b036
Added to database: 07/16/2026, 22:33:17 UTC
Last enriched: 07/23/2026, 22:50:17 UTC
Last updated: 08/30/2026, 10:52:08 UTC
Views: 76
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.