Executive brief
Virtuagym is a fitness and health platform with a mobile app and backend API that manages access to gym facilities. The vulnerability allows attackers to forge physical access QR codes indefinitely by exploiting hard-coded credentials embedded in the application, bypassing all password changes and logout mechanisms. This enables unauthorized physical access to restricted gym areas.
Technical details
The vulnerability stems from the use of a static, hard-coded parameter ('badge_number') as the HMAC private key for QR code generation. The badge_number value is exposed via the unauthenticated or low-privilege API endpoint '/club/_id_club_/member/_id_member_/resamania_qr_info'. An attacker with API access can extract this value and retrieve the application's cryptographic logic through reverse engineering of the unobfuscated APK, then generate valid QR codes indefinitely. This attack does not require ongoing authentication or user interaction; the attacker can forge codes for any member at any time, even after password changes or logout.
Affected products
- Virtuagym Virtuagym all versions
- Virtuagym Resamania Backend API all versions
Timeline
- 2026-08-26: disclosed: Published on NVD
- 2026-08-21: advisory: INCIBE-CERT advisory published (INCIBE-2026-576)