Junglewise Threat Intelligence

CVE-2026-43978: wger privilege escalation in trainer-login session chaining

CVE-2026-43978 · Severity: high · CVSS 8.1 · Published 2026-07-16

Technologies: Wger-Project Wger. Vendors: PyPI.

Executive brief

wger is an open-source fitness and workout management platform. A security flaw in the trainer login system allows a gym trainer to escalate their privileges to a gym manager or general manager account. By exploiting this, a trainer could gain full administrative control, allowing them to view sensitive member data, modify contracts, and access personal information of other staff members.

Technical details

A privilege escalation vulnerability exists in wger/core/views/user.py due to improper session flag validation in the trainer-login endpoint. The application uses a logical 'AND' condition to check for the 'gym.gym_trainer' permission and the 'trainer.identity' session flag; however, once a trainer successfully switches to a low-privileged user, the presence of the 'trainer.identity' flag causes the permission check to short-circuit. An attacker with trainer-level access can first switch to a regular user and then perform a second 'hop' to a manager account because the secondary protection block only triggers if the current user (now a regular user) holds trainer permissions. This allows an authenticated attacker to impersonate any higher-privileged user within the same gym. The issue is resolved in version 2.6 by ensuring the original trainer's permissions are verified during chained session hops.

Affected products

  • wger-project wger < 2.6

Timeline

  • 2026-05-14: advisory: GitHub Security Advisory published
  • 2026-07-16: disclosed: CVE published to NVD
  • 2026-07-16: patched: Fix confirmed in version 2.6

References

Related threats