Impact
The flaw lies in wger’s gym‑scope guard, which compares two gym objects with a simple inequality. When both operands are None the check always passes, allowing a trainer with gym_trainer and gym.add_adminusernote permissions and no gym assignment to read private data belonging to any other unaffiliated user. This includes admin notes, uploaded documents, gym contracts, user configuration, and permission data, constituting a significant information‑disclosure vulnerability classified as CWE‑863.
Affected Systems
The affected product is wger, the open‑source workout manager from the wger‑project. Versions prior to 2.6 contain the flaw; the five gym‑management views in those releases apply the faulty guard. Version 2.6 and later ship a fix that removes the None‑bypass.
Risk and Exploitability
The CVSS score of 7.1 signals a high‑severity flaw. EPSS is not available, so the exploitation probability is uncertain, but the attack can be executed locally by any logged‑in trainer users through the normal web interface, without requiring remote code execution or network compromise. Although the vulnerability is not listed in CISA’s KEV catalog, the potential for cross‑tenant data leakage makes it a priority for swift remediation.
OpenCVE Enrichment
Github GHSA