<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cve-2026-46434 - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/cve-2026-46434/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 07 Oct 2026 16:59:56 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/cve-2026-46434/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>wger Improper Privilege Management</title><link>https://feed.craftedsignal.io/briefs/2026-10-wger-privilege-escalation/</link><pubDate>Wed, 07 Oct 2026 16:59:56 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-wger-privilege-escalation/</guid><description>A privilege escalation vulnerability in wger allows gym trainers to deactivate higher-privileged accounts, resulting in administrative lockout.</description><content:encoded><![CDATA[<p>The wger workout manager (version 2.1 and earlier) contains an improper privilege management vulnerability (CVE-2026-46434) that allows a user with 'gym_trainer' permissions to deactivate accounts belonging to 'gym_manager' or 'general_gym_manager' roles within the same gym. The vulnerability exists because the <code>UserDeactivateView</code> and <code>UserActivateView</code> classes perform authorization using OR logic, which grants access if the requester possesses any of the permitted roles. Crucially, the application fails to verify whether the target user possesses a higher privilege level than the requester. Consequently, a malicious trainer can effectively lock out all gym managers, causing a denial of service for administrative operations. The issue is compounded by the fact that the 'trainer' role is always assignable by managers, allowing for the creation of accounts that can later be used to sabotage management access.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker obtains or creates a user account assigned to the 'gym_trainer' group within a target gym.</li>
<li>Attacker logs into the wger platform using the trainer credentials.</li>
<li>Attacker identifies the user ID for a 'gym_manager' or 'general_gym_manager' account operating within the same gym instance.</li>
<li>Attacker constructs a malicious request to the <code>UserDeactivateView</code> endpoint, specifically <code>GET /en/user/&lt;manager_user_id&gt;/deactivate</code>.</li>
<li>The application validates the requester's 'gym_trainer' permission as sufficient for access to the view.</li>
<li>The <code>dispatch()</code> method confirms the trainer and the target manager belong to the same gym.</li>
<li>The application executes the deactivation logic without verifying if the target has higher privileges.</li>
<li>The victim manager account is set to <code>is_active = False</code>, resulting in immediate lockout.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in a persistent denial of service for administrative users. Managers are unable to log in, manage gym members, or perform administrative tasks until manual intervention by a 'general_gym_manager' or superuser occurs. This directly impacts the integrity and availability of gym management operations.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Upgrade to a version of wger that includes the privilege hierarchy check in <code>UserDeactivateView</code> and <code>UserActivateView</code>.</li>
<li>Audit current gym user roles and remove unnecessary 'gym_trainer' permissions until the patch is applied.</li>
<li>Implement strict monitoring for access to <code>/deactivate</code> or <code>/activate</code> endpoints by users who do not possess 'gym_manager' permissions.</li>
<li>Ensure all Django superuser or 'general_gym_manager' accounts are protected with multi-factor authentication to prevent lockout by compromised lower-privileged accounts.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>privilege-escalation</category><category>web-application</category><category>cve-2026-46434</category><category>web-application-vulnerability</category><category>authorization-bypass</category><category>cve-2026-43976</category></item></channel></rss>