CVE-2026-46438: Broken Object Level Authorization in wger Workout Log Endpoint
Vulnerability ID: CVE-2026-46438
CVSS Score: 6.5
Published: 2026-10-07
CVE-2026-46438 is a critical Broken Object Level Authorization (BOLA) / Insecure Direct Object Reference (IDOR) vulnerability identified in the wger fitness manager prior to version 2.6. An authenticated attacker can exploit a missing authorization check on the slot_entry API parameter to inject unauthorized workout logs into another user's training schedule. This results in the corruption of the target user's automated progressive-overload calculations.
TL;DR
Missing validation in wger's API endpoints allows authenticated users to inject unauthorized training logs into any user's workout schedule by referencing their slot_entry ID, corrupting dynamic progressive-overload configurations.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-862 (Missing Authorization)
- Attack Vector: Network
- CVSS v3.1: 6.5 (Medium)
- Exploit Status: Proof of Concept (PoC) available
- Remediation: Official upgrade path to version 2.6
Affected Systems
- wger-project/wger
-
wger: < 2.6 (Fixed in:
2.6)
Code Analysis
Commit: b29cf17
Fix ownership checks for workout logs and slot entries
Mitigation Strategies
- Restrict user ownership configurations on all related sub-objects at both the controller layer and model validation layer.
- Isolate internal query relationships in calculation engines by strictly scoping lookups to the routine's owner user.
Remediation Steps:
- Upgrade the wger environment to version 2.6 or later.
- Audit active databases for existing cross-user references within the WorkoutLog tables and prune inconsistent records.
- Enable monitoring for HTTP 403 Forbidden responses on the workout log REST API endpoints.
References
Read the full report for CVE-2026-46438 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)