wger Improper Privilege Management
A privilege escalation vulnerability in wger allows gym trainers to deactivate higher-privileged accounts, resulting in administrative lockout.
CVE search metadata
CVE search record: CVE-2026-46434. Severity: high. CVSS: 7.1. KEV: no. Product: wger (<= 2.1). Brief: wger Improper Privilege Management. Brief link: https://feed.craftedsignal.io/briefs/2026-10-wger-privilege-escalation/
What's new
- 1. added detection rule: Detect wger Authorization Bypass Attempts - CVE-2026-43976 Oct 7, 17:00 via ghsa
The wger workout manager (version 2.1 and earlier) contains an improper privilege management vulnerability (CVE-2026-46434) that allows a user with 'gym_trainer' permissions to deactivate accounts belonging to 'gym_manager' or 'general_gym_manager' roles within the same gym. The vulnerability exists because the UserDeactivateView and UserActivateView classes perform authorization using OR logic, which grants access if the requester possesses any of the permitted roles. Crucially, the application fails to verify whether the target user possesses a higher privilege level than the requester. Consequently, a malicious trainer can effectively lock out all gym managers, causing a denial of service for administrative operations. The issue is compounded by the fact that the 'trainer' role is always assignable by managers, allowing for the creation of accounts that can later be used to sabotage management access.
Attack Chain
- Attacker obtains or creates a user account assigned to the 'gym_trainer' group within a target gym.
- Attacker logs into the wger platform using the trainer credentials.
- Attacker identifies the user ID for a 'gym_manager' or 'general_gym_manager' account operating within the same gym instance.
- Attacker constructs a malicious request to the
UserDeactivateViewendpoint, specificallyGET /en/user/<manager_user_id>/deactivate. - The application validates the requester's 'gym_trainer' permission as sufficient for access to the view.
- The
dispatch()method confirms the trainer and the target manager belong to the same gym. - The application executes the deactivation logic without verifying if the target has higher privileges.
- The victim manager account is set to
is_active = False, resulting in immediate lockout.
Impact
Successful exploitation results in a persistent denial of service for administrative users. Managers are unable to log in, manage gym members, or perform administrative tasks until manual intervention by a 'general_gym_manager' or superuser occurs. This directly impacts the integrity and availability of gym management operations.
Recommendation
- Upgrade to a version of wger that includes the privilege hierarchy check in
UserDeactivateViewandUserActivateView. - Audit current gym user roles and remove unnecessary 'gym_trainer' permissions until the patch is applied.
- Implement strict monitoring for access to
/deactivateor/activateendpoints by users who do not possess 'gym_manager' permissions. - Ensure all Django superuser or 'general_gym_manager' accounts are protected with multi-factor authentication to prevent lockout by compromised lower-privileged accounts.
Immediate actions
Upgrade wger to 2.6 or later
Threat Hunt
Identify accounts with 'gym_trainer' role performing actions on 'gym_manager' accounts
Data: Web server logs or application access logs
Mitigations
Patch wger to 2.6 or later
CVE-2026-46434
Detection coverage 1
Detect wger Authorization Bypass Attempts - CVE-2026-43976
highDetects unauthorized access attempts to wger gym management endpoints by flagging potential enumeration of user IDs across sensitive paths.
Detection queries are available on the platform. Get full rules →