PatchSiren cyber security CVE debrief
CVE-2026-46434 wger-project CVE debrief
A vulnerability in wger allows a user with the `gym_trainer` permission to deactivate any account in the same gym, including higher-privileged roles like `gym_manager` and `general_gym_manager`. This is due to the `UserDeactivateView` permitting access with any one of `gym.manage_gym`, `gym.manage_gyms`, or `gym.gym_trainer` permissions without proper privilege hierarchy checks.
- Vendor
- wger-project
- Product
- wger
- CVSS
- HIGH 7.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-07
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-07
- Advisory updated
- 2026-10-07
Who should care
Defenders managing wger deployments, especially those with `gym_trainer` roles, should assess exposure and potential impact. They should verify wger version and configuration, restrict `gym_trainer` permissions, and monitor for suspicious activity. Additionally, security teams and vulnerability management teams should be aware of the potential risks and plan accordingly.
Why it matters
CVE-2026-46434 allows users with `gym_trainer` permissions in wger to deactivate higher-privileged accounts, posing a risk of privilege escalation and unauthorized access. Defenders should verify exposure, restrict permissions, and monitor for suspicious activity.
- Potential unauthorized account deactivation by lower-privileged users.
- Elevation of privileges through permission misuse.
- Increased risk of targeted attacks on higher-privileged accounts.
- Need for verification of wger version and configuration.
Technical summary
The `UserDeactivateView` in wger allows users with `gym_trainer` permission to deactivate any account in the same gym due to OR logic in permission checks, lacking proper privilege hierarchy verification. This issue arises from the `WgerMultiplePermissionRequiredMixin` treating the required permissions as an OR condition, enabling lower-privileged users to perform actions typically restricted to higher-privileged roles. Affected deployments should assess the impact of potential account deactivation by lower-privileged users and consider mitigating actions.
Defensive priority
Defenders should prioritize verifying exposure in their wger deployments, especially where `gym_trainer` roles exist, and assess the impact of potential account deactivation by lower-privileged users.
Recommended defensive actions
- Verify wger version and deployment configuration to assess exposure.
- Restrict `gym_trainer` permissions to necessary users.
- Monitor for unauthorized account deactivation attempts.
- Consider upgrading to a patched version if available.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The vulnerability is confirmed in wger versions up to 2.1. The CVE Program and NVD provide official records, but details on affected versions and patches are limited in the provided corpus. Defenders should verify wger version and configuration to assess exposure. Evidence is based on source item details and official CVE/NVD records, but additional information may be needed for comprehensive risk assessment.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-46434 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-46434
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-46434 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-46434
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
wger: Trainer Privilege Escalation - Improper Privilege Management
Unverified legacy reference
URL: https://storage.googleapis.com/osv-vulnerabilities/PyPI/GHSA-x249-cx55-2h87.json
osv_dev
-
Source reference
Unverified legacy reference
URL: https://github.com/wger-project/wger/security/advisories/GHSA-x249-cx55-2h87
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/wger-project/wger
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/wger-project/wger/releases/tag/2.6
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.