wger is a free, open-source workout and fitness manager. Prior to version 2.6, five gym management views in wger apply a flawed gym-scope guard (`gym_a != gym_b`) that silently passes when both operands are `None`. A trainer with `gym.gym_trainer` and `gym.add_adminusernote` permissions and no gym assignment (`gym=None`) can read private admin notes, uploaded documents, gym contracts, user configuration, and user permission data for **any other unaffiliated user** on the instance. The subsequent querysets filter only on the attacker-supplied `member_id` with no secondary gym-scoped validation, so all records are disclosed. Version 2.6 fixes the issue.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-c72h-82w6-rqfp | wger: cross-tenant admin notes/contracts leak via gym=None bypass (5 views) |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 07 Oct 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wger-project
Wger-project wger |
|
| Vendors & Products |
Wger-project
Wger-project wger |
Wed, 07 Oct 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | wger is a free, open-source workout and fitness manager. Prior to version 2.6, five gym management views in wger apply a flawed gym-scope guard (`gym_a != gym_b`) that silently passes when both operands are `None`. A trainer with `gym.gym_trainer` and `gym.add_adminusernote` permissions and no gym assignment (`gym=None`) can read private admin notes, uploaded documents, gym contracts, user configuration, and user permission data for **any other unaffiliated user** on the instance. The subsequent querysets filter only on the attacker-supplied `member_id` with no secondary gym-scoped validation, so all records are disclosed. Version 2.6 fixes the issue. | |
| Title | wger: cross-tenant admin notes/contracts leak via gym=None bypass (5 views) | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-07T13:33:11.008Z
Reserved: 2026-05-04T20:24:31.915Z
Link: CVE-2026-43976
No data.
Status : Deferred
Published: 2026-10-07T14:17:09.887
Modified: 2026-10-07T14:46:03.387
Link: CVE-2026-43976
No data.
OpenCVE Enrichment
Updated: 2026-10-07T15:45:06Z
Weaknesses
Github GHSA