Skip to content
Threat Feed
high advisory

wger Improper Privilege Management

A privilege escalation vulnerability in wger allows gym trainers to deactivate higher-privileged accounts, resulting in administrative lockout.

CVE search metadata

CVE search record: CVE-2026-46434. Severity: high. CVSS: 7.1. KEV: no. Product: wger (<= 2.1). Brief: wger Improper Privilege Management. Brief link: https://feed.craftedsignal.io/briefs/2026-10-wger-privilege-escalation/

What's new

  • 1. added detection rule: Detect wger Authorization Bypass Attempts - CVE-2026-43976 Oct 7, 17:00 via ghsa

The wger workout manager (version 2.1 and earlier) contains an improper privilege management vulnerability (CVE-2026-46434) that allows a user with 'gym_trainer' permissions to deactivate accounts belonging to 'gym_manager' or 'general_gym_manager' roles within the same gym. The vulnerability exists because the UserDeactivateView and UserActivateView classes perform authorization using OR logic, which grants access if the requester possesses any of the permitted roles. Crucially, the application fails to verify whether the target user possesses a higher privilege level than the requester. Consequently, a malicious trainer can effectively lock out all gym managers, causing a denial of service for administrative operations. The issue is compounded by the fact that the 'trainer' role is always assignable by managers, allowing for the creation of accounts that can later be used to sabotage management access.

Attack Chain

  1. Attacker obtains or creates a user account assigned to the 'gym_trainer' group within a target gym.
  2. Attacker logs into the wger platform using the trainer credentials.
  3. Attacker identifies the user ID for a 'gym_manager' or 'general_gym_manager' account operating within the same gym instance.
  4. Attacker constructs a malicious request to the UserDeactivateView endpoint, specifically GET /en/user/<manager_user_id>/deactivate.
  5. The application validates the requester's 'gym_trainer' permission as sufficient for access to the view.
  6. The dispatch() method confirms the trainer and the target manager belong to the same gym.
  7. The application executes the deactivation logic without verifying if the target has higher privileges.
  8. The victim manager account is set to is_active = False, resulting in immediate lockout.

Impact

Successful exploitation results in a persistent denial of service for administrative users. Managers are unable to log in, manage gym members, or perform administrative tasks until manual intervention by a 'general_gym_manager' or superuser occurs. This directly impacts the integrity and availability of gym management operations.

Recommendation

  1. Upgrade to a version of wger that includes the privilege hierarchy check in UserDeactivateView and UserActivateView.
  2. Audit current gym user roles and remove unnecessary 'gym_trainer' permissions until the patch is applied.
  3. Implement strict monitoring for access to /deactivate or /activate endpoints by users who do not possess 'gym_manager' permissions.
  4. Ensure all Django superuser or 'general_gym_manager' accounts are protected with multi-factor authentication to prevent lockout by compromised lower-privileged accounts.

Immediate actions

Upgrade wger to 2.6 or later

IT Operations 48h

Threat Hunt

Identify accounts with 'gym_trainer' role performing actions on 'gym_manager' accounts

T1068 high high confidence hunt now

Data: Web server logs or application access logs

Mitigations

Patch wger to 2.6 or later

immediate IT Operations

CVE-2026-46434

Detection coverage 1

Detect wger Authorization Bypass Attempts - CVE-2026-43976

high

Detects unauthorized access attempts to wger gym management endpoints by flagging potential enumeration of user IDs across sensitive paths.

sigma tactics: initial_access techniques: T1068 sources: webserver

Detection queries are available on the platform. Get full rules →