PT-2026-22203 · Wger · Wger

Byamb4

·

Published

2026-02-26

·

Updated

2026-02-27

·

CVE-2026-27835

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions wger versions prior to 2.4
Description wger is a free, open-source workout and fitness manager. Versions up to and including 2.4 improperly handle user data retrieval. The RepetitionsConfigViewSet and MaxRepetitionsConfigViewSet API endpoints return all users' repetition configuration data because the get queryset() function calls .all() instead of filtering by the authenticated user (user). This allows any registered user to enumerate the workout structure of every other user. The API endpoints involved are RepetitionsConfigViewSet and MaxRepetitionsConfigViewSet. The vulnerable function is get queryset().
Recommendations Update to a version later than 2.4.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-27835
GHSA-XF68-8HJW-7MPM

Affected Products

Wger