Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-43976— wger: cross-tenant admin notes/contracts leak via gym=None bypass (5 views)

Quick assessment

Affected
wger-project wger
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

wger 是一款免费且开源的健身训练与健康管理软件。在 2.6 版本之前,wger 中有五个健身房管理视图存在缺陷:它们使用了不正确的健身房范围检查机制( ),当两个操作数均为 时,该检查会静默通过。拥有 和 权限但未关联任何健身房(即 )的训练师,可以读取实例中任何其他未关联用户的私人管理员备注、上传的文档、健身房合同、用户配置以及用户权限数据。后续的查询集仅根据攻击者提供的 进行过滤,缺乏额外的健身房范围验证,从而导致所有相关记录被泄露。该问题已在版本 2.6 中修复。

CVSS 7.1 · High

Possible ATT&CK Techniques 1 AI

T1530 · Data from Cloud Storage
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-43976

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
wger: cross-tenant admin notes/contracts leak via gym=None bypass (5 views)
Source: CVE Program / CVE List V5
Vulnerability Description
wger is a free, open-source workout and fitness manager. Prior to version 2.6, five gym management views in wger apply a flawed gym-scope guard (`gym_a != gym_b`) that silently passes when both operands are `None`. A trainer with `gym.gym_trainer` and `gym.add_adminusernote` permissions and no gym assignment (`gym=None`) can read private admin notes, uploaded documents, gym contracts, user configuration, and user permission data for **any other unaffiliated user** on the instance. The subsequent querysets filter only on the attacker-supplied `member_id` with no secondary gym-scoped validation, so all records are disclosed. Version 2.6 fixes the issue.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制不正确
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
wger-project wger < 2.6 -

II. Public POCs for CVE-2026-43976

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-43976

请登录查看更多情报信息。

Other References for CVE-2026-43976 (2)

Same Patch Batch · wger-project · 2026-10-07 · 5 CVEs total

CVE-2026-46434 7.1 HIGH wger: Trainer Privilege Escalation - Improper Privilege Management
CVE-2026-46438 6.5 MEDIUM wger: Cross-User Data Corruption via Missing Ownership Check on WorkoutLog.slot_entry
CVE-2026-45161 5.4 MEDIUM wger: trainer_login accepts GET - CSRF bypass enables forced session rebinding
CVE-2026-46437 4.8 MEDIUM wger: API credentials remain valid after logout/password change

IV. Related Vulnerabilities

V. Comments for CVE-2026-43976

No comments yet


Leave a comment