PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-46434 wger-project CVE debrief

A vulnerability in wger allows a user with the `gym_trainer` permission to deactivate any account in the same gym, including higher-privileged roles like `gym_manager` and `general_gym_manager`. This is due to the `UserDeactivateView` permitting access with any one of `gym.manage_gym`, `gym.manage_gyms`, or `gym.gym_trainer` permissions without proper privilege hierarchy checks.

Vendor
wger-project
Product
wger
CVSS
HIGH 7.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-07
Original CVE updated
2026-10-07
Advisory published
2026-10-07
Advisory updated
2026-10-07

Who should care

Defenders managing wger deployments, especially those with `gym_trainer` roles, should assess exposure and potential impact. They should verify wger version and configuration, restrict `gym_trainer` permissions, and monitor for suspicious activity. Additionally, security teams and vulnerability management teams should be aware of the potential risks and plan accordingly.

Why it matters

CVE-2026-46434 allows users with `gym_trainer` permissions in wger to deactivate higher-privileged accounts, posing a risk of privilege escalation and unauthorized access. Defenders should verify exposure, restrict permissions, and monitor for suspicious activity.

  • Potential unauthorized account deactivation by lower-privileged users.
  • Elevation of privileges through permission misuse.
  • Increased risk of targeted attacks on higher-privileged accounts.
  • Need for verification of wger version and configuration.

Technical summary

The `UserDeactivateView` in wger allows users with `gym_trainer` permission to deactivate any account in the same gym due to OR logic in permission checks, lacking proper privilege hierarchy verification. This issue arises from the `WgerMultiplePermissionRequiredMixin` treating the required permissions as an OR condition, enabling lower-privileged users to perform actions typically restricted to higher-privileged roles. Affected deployments should assess the impact of potential account deactivation by lower-privileged users and consider mitigating actions.

Defensive priority

Defenders should prioritize verifying exposure in their wger deployments, especially where `gym_trainer` roles exist, and assess the impact of potential account deactivation by lower-privileged users.

Recommended defensive actions

  • Verify wger version and deployment configuration to assess exposure.
  • Restrict `gym_trainer` permissions to necessary users.
  • Monitor for unauthorized account deactivation attempts.
  • Consider upgrading to a patched version if available.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The vulnerability is confirmed in wger versions up to 2.1. The CVE Program and NVD provide official records, but details on affected versions and patches are limited in the provided corpus. Defenders should verify wger version and configuration to assess exposure. Evidence is based on source item details and official CVE/NVD records, but additional information may be needed for comprehensive risk assessment.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-46434 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-46434

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-46434 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-46434

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.