No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-x249-cx55-2h87 | wger: Trainer Privilege Escalation - Improper Privilege Management |
Wed, 07 Oct 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 07 Oct 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | wger is a free, open-source workout and fitness manager. Prior to version 2.6, a user with only the `gym_trainer` permission can deactivate any account in the same gym, including `gym_manager` and `general_gym_manager` accounts. The `UserDeactivateView` grants access to anyone holding any one of `gym.manage_gym`, `gym.manage_gyms`, or `gym.gym_trainer` (OR logic via `WgerMultiplePermissionRequiredMixin`), and performs no privilege-hierarchy check to prevent a lower-privileged role from disabling a higher-privileged one. Version 2.6 fixes the issue. | |
| Title | wger: Trainer Privilege Escalation - Improper Privilege Management | |
| Weaknesses | CWE-269 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-07T14:35:38.960Z
Reserved: 2026-05-13T22:18:22.830Z
Link: CVE-2026-46434
Updated: 2026-10-07T14:35:35.641Z
Status : Deferred
Published: 2026-10-07T14:17:10.277
Modified: 2026-10-07T15:17:20.877
Link: CVE-2026-46434
No data.
OpenCVE Enrichment
No data.
-
CWE-269
Improper Privilege Management
Github GHSA