{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/wger--2.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:wger:wger:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.1,"id":"CVE-2026-46434"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["wger (\u003c= 2.1)"],"_cs_severities":["high"],"_cs_tags":["privilege-escalation","web-application","cve-2026-46434","web-application-vulnerability","authorization-bypass","cve-2026-43976"],"_cs_type":"advisory","_cs_vendors":["wger"],"content_html":"\u003cp\u003eThe wger workout manager (version 2.1 and earlier) contains an improper privilege management vulnerability (CVE-2026-46434) that allows a user with 'gym_trainer' permissions to deactivate accounts belonging to 'gym_manager' or 'general_gym_manager' roles within the same gym. The vulnerability exists because the \u003ccode\u003eUserDeactivateView\u003c/code\u003e and \u003ccode\u003eUserActivateView\u003c/code\u003e classes perform authorization using OR logic, which grants access if the requester possesses any of the permitted roles. Crucially, the application fails to verify whether the target user possesses a higher privilege level than the requester. Consequently, a malicious trainer can effectively lock out all gym managers, causing a denial of service for administrative operations. The issue is compounded by the fact that the 'trainer' role is always assignable by managers, allowing for the creation of accounts that can later be used to sabotage management access.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker obtains or creates a user account assigned to the 'gym_trainer' group within a target gym.\u003c/li\u003e\n\u003cli\u003eAttacker logs into the wger platform using the trainer credentials.\u003c/li\u003e\n\u003cli\u003eAttacker identifies the user ID for a 'gym_manager' or 'general_gym_manager' account operating within the same gym instance.\u003c/li\u003e\n\u003cli\u003eAttacker constructs a malicious request to the \u003ccode\u003eUserDeactivateView\u003c/code\u003e endpoint, specifically \u003ccode\u003eGET /en/user/\u0026lt;manager_user_id\u0026gt;/deactivate\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe application validates the requester's 'gym_trainer' permission as sufficient for access to the view.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003edispatch()\u003c/code\u003e method confirms the trainer and the target manager belong to the same gym.\u003c/li\u003e\n\u003cli\u003eThe application executes the deactivation logic without verifying if the target has higher privileges.\u003c/li\u003e\n\u003cli\u003eThe victim manager account is set to \u003ccode\u003eis_active = False\u003c/code\u003e, resulting in immediate lockout.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in a persistent denial of service for administrative users. Managers are unable to log in, manage gym members, or perform administrative tasks until manual intervention by a 'general_gym_manager' or superuser occurs. This directly impacts the integrity and availability of gym management operations.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade to a version of wger that includes the privilege hierarchy check in \u003ccode\u003eUserDeactivateView\u003c/code\u003e and \u003ccode\u003eUserActivateView\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eAudit current gym user roles and remove unnecessary 'gym_trainer' permissions until the patch is applied.\u003c/li\u003e\n\u003cli\u003eImplement strict monitoring for access to \u003ccode\u003e/deactivate\u003c/code\u003e or \u003ccode\u003e/activate\u003c/code\u003e endpoints by users who do not possess 'gym_manager' permissions.\u003c/li\u003e\n\u003cli\u003eEnsure all Django superuser or 'general_gym_manager' accounts are protected with multi-factor authentication to prevent lockout by compromised lower-privileged accounts.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-07T17:00:12Z","date_published":"2026-10-07T16:59:56Z","id":"https://feed.craftedsignal.io/briefs/2026-10-wger-privilege-escalation/","summary":"A privilege escalation vulnerability in wger allows gym trainers to deactivate higher-privileged accounts, resulting in administrative lockout.","title":"wger Improper Privilege Management","url":"https://feed.craftedsignal.io/briefs/2026-10-wger-privilege-escalation/"}],"language":"en","title":"CraftedSignal Threat Feed - Wger (\u003c= 2.1)","version":"https://jsonfeed.org/version/1.1"}