Junglewise Threat Intelligence

CVE-2026-27838: PYSEC-2026-3418 - wger: IDOR via user-unscoped cache keys on routine API actions exposes workout data

CVE-2026-27838 · Severity: low · CVSS 3.1 · Published 2026-07-13

Technologies: wger (PyPI). Vendors: PyPI.

Executive brief

wger: IDOR via user-unscoped cache keys on routine API actions exposes workout data

Affected products

  • PyPI wger

Related threats