DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-46438: CVE-2026-46438: Broken Object Level Authorization in wger Workout Log Endpoint

CVE-2026-46438: Broken Object Level Authorization in wger Workout Log Endpoint

Vulnerability ID: CVE-2026-46438
CVSS Score: 6.5
Published: 2026-10-07

CVE-2026-46438 is a critical Broken Object Level Authorization (BOLA) / Insecure Direct Object Reference (IDOR) vulnerability identified in the wger fitness manager prior to version 2.6. An authenticated attacker can exploit a missing authorization check on the slot_entry API parameter to inject unauthorized workout logs into another user's training schedule. This results in the corruption of the target user's automated progressive-overload calculations.

TL;DR

Missing validation in wger's API endpoints allows authenticated users to inject unauthorized training logs into any user's workout schedule by referencing their slot_entry ID, corrupting dynamic progressive-overload configurations.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-862 (Missing Authorization)
  • Attack Vector: Network
  • CVSS v3.1: 6.5 (Medium)
  • Exploit Status: Proof of Concept (PoC) available
  • Remediation: Official upgrade path to version 2.6

Affected Systems

  • wger-project/wger
  • wger: < 2.6 (Fixed in: 2.6)

Code Analysis

Commit: b29cf17

Fix ownership checks for workout logs and slot entries

Mitigation Strategies

  • Restrict user ownership configurations on all related sub-objects at both the controller layer and model validation layer.
  • Isolate internal query relationships in calculation engines by strictly scoping lookups to the routine's owner user.

Remediation Steps:

  1. Upgrade the wger environment to version 2.6 or later.
  2. Audit active databases for existing cross-user references within the WorkoutLog tables and prune inconsistent records.
  3. Enable monitoring for HTTP 403 Forbidden responses on the workout log REST API endpoints.

References


Read the full report for CVE-2026-46438 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)