Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-rjpf-7pf5-q54x | wger: Cross-User Data Corruption via Missing Ownership Check on WorkoutLog.slot_entry |
Wed, 07 Oct 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | wger is a free, open-source workout and fitness manager. Prior to version 2.6, an authenticated attacker can inject arbitrary workout log entries into any other user's `SlotEntry` by supplying the victim's `slot_entry` ID in a `POST /api/v2/workoutlog/` request. The `slot_entry` foreign key is not included in the ownership verification performed by `WorkoutLogViewSet.get_owner_objects()`, so the server accepts and persists the cross-user reference without error. Because `SlotEntry.get_config_data()` retrieves associated logs via `self.workoutlog_set.all()` with no user filter, the attacker's injected data is silently folded into the victim's progressive-overload calculations, corrupting their auto-generated weight and repetition targets. Version 2.6 contains a patch. | |
| Title | wger: Cross-User Data Corruption via Missing Ownership Check on WorkoutLog.slot_entry | |
| Weaknesses | CWE-639 CWE-862 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-07T14:00:10.046Z
Reserved: 2026-05-13T22:18:22.830Z
Link: CVE-2026-46438
No data.
Status : Deferred
Published: 2026-10-07T14:17:10.650
Modified: 2026-10-07T14:46:03.387
Link: CVE-2026-46438
No data.
OpenCVE Enrichment
No data.
Github GHSA