Executive brief
wger is an open-source fitness and workout management platform. A security flaw in the trainer login system allows a gym trainer to escalate their privileges to a gym manager or general manager account. By exploiting this, a trainer could gain full administrative control, allowing them to view sensitive member data, modify contracts, and access personal information of other staff members.
Technical details
A privilege escalation vulnerability exists in wger/core/views/user.py due to improper session flag validation in the trainer-login endpoint. The application uses a logical 'AND' condition to check for the 'gym.gym_trainer' permission and the 'trainer.identity' session flag; however, once a trainer successfully switches to a low-privileged user, the presence of the 'trainer.identity' flag causes the permission check to short-circuit. An attacker with trainer-level access can first switch to a regular user and then perform a second 'hop' to a manager account because the secondary protection block only triggers if the current user (now a regular user) holds trainer permissions. This allows an authenticated attacker to impersonate any higher-privileged user within the same gym. The issue is resolved in version 2.6 by ensuring the original trainer's permissions are verified during chained session hops.
Affected products
- wger-project wger < 2.6
Timeline
- 2026-05-14: advisory: GitHub Security Advisory published
- 2026-07-16: disclosed: CVE published to NVD
- 2026-07-16: patched: Fix confirmed in version 2.6