Junglewise Threat Intelligence

CVE-2026-86254: wger incomplete authorization bypass in user management views

CVE-2026-86254 · Severity: medium · CVSS 6.8 · Published 2026-09-06

Technologies: Wger Project Wger.

Executive brief

wger is a Django-based fitness management and tracking platform. An incomplete authorization fix allows gym staff members with administrative permissions but no assigned gym affiliation to delete user accounts, lock users out by deactivating them, or reactivate deactivated users across the entire system. This bypasses the intended tenant isolation controls, enabling account takeover and denial of service against other users.

Technical details

The vulnerability is an authorization bypass in wger/core/views/user.py where three views (UserDeactivateView, UserActivateView, and delete) use raw integer comparison (gym_id != ...) instead of the corrected is_same_gym() helper function to enforce gym-scope boundaries. The root cause is a failed patch: a prior fix (CVE-2026-43948) added is_same_gym() to five views in wger/gym/views/ but left three views in wger/core/views/user.py unpatched. The bug exploits Python's None != None evaluation returning False, allowing users with gym=None (default unassigned state) and gym.manage_gym permission to bypass the authorization check and perform write operations on any other user with gym=None. An attacker can permanently delete accounts, deactivate users (locking them out), or reactivate deactivated users. User enumeration is trivial via sequential primary keys. No patch is currently available for the affected views.

Affected products

  • wger project wger through master (as of 2026-05-08)

Timeline

  • 2026-09-06: disclosed: CVE-2026-86254 published by NVD
  • 2026-05-14: advisory: GHSA-mw8f-w6p8-xrf4 published; incomplete fix discovered
  • 2026-04-28: other: Prior incomplete fix (CVE-2026-43948 / GHSA-mhc8-p3jx-84mm) patched five of eight affected views

References