CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



CVE-2026-46438

CVE-2026-46438: Broken Object Level Authorization in wger Workout Log Endpoint

Amit Schendel
Amit Schendel
Senior Security Researcher

Oct 7, 2026·5 min read·7 visits

Executive Summary (TL;DR)

Missing validation in wger's API endpoints allows authenticated users to inject unauthorized training logs into any user's workout schedule by referencing their slot_entry ID, corrupting dynamic progressive-overload configurations.

CVE-2026-46438 is a critical Broken Object Level Authorization (BOLA) / Insecure Direct Object Reference (IDOR) vulnerability identified in the wger fitness manager prior to version 2.6. An authenticated attacker can exploit a missing authorization check on the slot_entry API parameter to inject unauthorized workout logs into another user's training schedule. This results in the corruption of the target user's automated progressive-overload calculations.

Vulnerability Overview

The open-source fitness manager wger exposes standard REST API endpoints to facilitate the tracking of workouts, routines, and user logs. Within its multi-tenant architecture, isolation is enforced at the controller level to prevent cross-user data interference.

In versions prior to 2.6, the api validation layer failed to enforce appropriate object-level authorization on several relational fields. Specifically, the model controller representing workout logs neglected to map parent-child relationships for the slot_entry entity.

Consequently, an authenticated user could issue requests containing database identifiers referencing assets owned by unrelated accounts. The backend accepted and committed these associations, breaking logical boundaries between tenants and enabling unauthorized state modification.

Root Cause Analysis

The Django REST Framework integration in wger uses a custom superclass named WgerOwnerObjectModelViewSet to automate owner-based authorization checks during model creation and modification. This controller interceptor evaluates properties provided in the API request against a registration list returned by get_owner_objects().

Prior to the implementation of the security patch, the WorkoutLogViewSet class in wger/manager/api/views.py only evaluated Routine and WorkoutSession fields for ownership validation. The slot_entry parameter, which links a specific log entry to a scheduled slot, was omitted from the list.

Because of this omission, when an authenticated client submitted a POST request containing a foreign slot_entry identifier, the system only validated ownership of the auxiliary routine identifier. The database saved the record, creating an Insecure Direct Object Reference (IDOR) state.

A secondary failure point exists in the query logic of the calculation engine located in wger/manager/models/slot_entry.py. The SlotEntry.get_config_data() method loaded all logs connected to the slot entry without validating their ownership. This design defect allowed the attacker's unauthorized records to pollute the automated training statistics generation pipeline.

Code Analysis

To understand the technical changes, we examine the diff from the security patch applied to the code repository. The primary vulnerability resided in the registration parameters of the REST API controller.

# Vulnerable configuration in wger/manager/api/views.py
class WorkoutLogViewSet(WgerOwnerObjectModelViewSet):
    def get_owner_objects(self):
        return [(Routine, 'routine'), (WorkoutSession, 'session')]

The patched viewset updates the return value of get_owner_objects to enforce validation checks against both the slot_entry and the recursive next_log fields.

# Patched configuration in wger/manager/api/views.py
class WorkoutLogViewSet(WgerOwnerObjectModelViewSet):
    def get_owner_objects(self):
        return [
            (Routine, 'routine'),
            (WorkoutSession, 'session'),
            (SlotEntry, 'slot_entry'),
            (WorkoutLog, 'next_log'),
        ]

Furthermore, model-level security guarantees were added within the database persistence interface in wger/manager/models/log.py. This ensures that even if API controllers are bypassed, direct model updates fail authorization validation.

# Patched validation in wger/manager/models/log.py
def save(self, *args, **kwargs):
    if self.routine and self.routine.user != self.user:
        return
    if self.slot_entry and self.slot_entry.slot.day.routine.user != self.user:
        return

Exploitation Methodology

An attacker requires a valid authenticated session to exploit this vulnerability. The vulnerability requires no administrative privileges and can be triggered using a standard client connection.

The attack process initiates with sequential scanning of integer identifiers associated with targeted slot_entry objects. Because these identifiers are auto-incrementing, discovery is straightforward.

Upon identifying a target identifier, the attacker constructs a POST payload specifying a legitimate routine identifier owned by the attacker alongside the target slot_entry identifier owned by the victim. The application server processes the request, bypasses checking on the slot_entry property, and logs the malicious telemetry.

Impact Assessment

The primary impact of this vulnerability is unauthorized data manipulation and integrity corruption within user profiles. Because wger automates progress tracking via calculation engines, the presence of unauthorized workout logs corrupts the statistical baseline of the targeted athlete.

Specifically, the progressive-overload scheduling module relies on historical weight and repetition limits to project upcoming goals. Injecting extreme or incorrect values forces the application to calculate unreachable targets, impairing the usability of the software.

While the vulnerability does not lead directly to arbitrary code execution or data extraction, the complete loss of multi-tenant integrity across relational workout records introduces a significant trust barrier in shared deployments.

Remediation & Defensive Mitigation

The primary remediation mechanism is the installation of wger version 2.6. This release closes the authorization gap in the API controllers and enforces defensive validation constraints inside the underlying models.

For system administrators who cannot perform immediate platform updates, temporary relief is achievable by auditing database transactions and filtering suspicious logs. Running targeted database queries can expose instances where log records point to incompatible parent accounts.

Additionally, Web Application Firewalls (WAF) can be configured to block suspicious requests directed at the API endpoint. Inspecting incoming request bodies for mismatching parameters helps reduce the potential attack surface.

Fix Analysis (1)

Technical Appendix

CVSS Score
6.5/ 10
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Affected Systems

wger-project/wger

Affected Versions Detail

Product
Affected Versions
Fixed Version
wger
wger-project
< 2.62.6
AttributeDetail
CWE IDCWE-862 (Missing Authorization)
Attack VectorNetwork
CVSS v3.16.5 (Medium)
Exploit StatusProof of Concept (PoC) available
RemediationOfficial upgrade path to version 2.6

MITRE ATT&CK Mapping

T1068Exploitation for Privilege Escalation
Privilege Escalation
CWE-862
Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Vulnerability Timeline

Vulnerability patched and wger 2.6 released
2026-05-08
GitHub Security Advisory published and CVE-2026-46438 assigned
2026-10-07

References & Sources

  • [1]GitHub Security Advisory GHSA-rjpf-7pf5-q54x
  • [2]Patch Commit b29cf178651bbcc243d21673932e32bd42017893

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•1 minute ago•CVE-2026-106443
8.8

CVE-2026-106443: Remote Code Execution in WeasyPrint via Unvalidated Pillow EPS Processing

A critical remote code execution vulnerability was identified in WeasyPrint prior to version 70.0. When compiling HTML containing a malicious Encapsulated PostScript (EPS) graphic on a host with Ghostscript installed, Pillow invokes Ghostscript to process the image, executing arbitrary PostScript commands.

Amit Schendel
Amit Schendel
0 views•8 min read
•about 1 hour ago•CVE-2026-106489
6.5

CVE-2026-106489: Authorization Bypass via Path Traversal in Spotify Backstage TechDocs Backend

An authorization bypass vulnerability in the Spotify Backstage TechDocs backend plugin allows authenticated attackers with access to at least one valid TechDocs site to read arbitrary static documentation from other entities. This occurs due to un-sanitized relative subpaths passing directly to external storage drivers.

Alon Barad
Alon Barad
3 views•7 min read
•about 2 hours ago•CVE-2026-106502
5.3

CVE-2026-106502: Sensitive Information Exposure in Backstage Scaffolder Backend

The @backstage/plugin-scaffolder-backend package prior to version 4.1.0 is vulnerable to sensitive information exposure in Scaffolder task failure events. Under specific template and failure conditions, an authenticated user can retrieve backend-managed credentials, such as VCS access tokens and API keys, from affected task execution events and stored database logs. This vulnerability has been remediated in version 4.1.0 of the package and is bundled with the Backstage platform release v1.54.6.

Amit Schendel
Amit Schendel
4 views•6 min read
•about 3 hours ago•CVE-2026-61436
8.6

CVE-2026-61436: Missing Webhook Signature Verification in PraisonAI AgentMail Endpoint

A critical security flaw exists in PraisonAI before version 4.6.78 when operating in AgentMail webhook mode. The application processes incoming POST requests without checking for cryptographic signatures, allowing unauthenticated attackers to forge emails, spoof identities, and force AI agents to execute unauthorized operations.

Amit Schendel
Amit Schendel
4 views•7 min read
•about 4 hours ago•CVE-2026-62179
6.5

CVE-2026-62179: Missing Authorization in praisonai-platform Dependency Deletion Route

A missing authorization vulnerability (CWE-862) exists in praisonai-platform versions prior to 0.1.9, allowing low-privileged workspace members to delete planning dependencies on issues owned by administrators by routing the deletion request through an attacker-owned issue.

Amit Schendel
Amit Schendel
3 views•6 min read
•about 11 hours ago•CVE-2026-105795
3.1

CVE-2026-105795: Unvalidated Custom Extension Path Traversal in Microsoft Kiota

CVE-2026-105795 (GHSA-6gw6-rv2g-25mg) is a critical path traversal vulnerability in Microsoft Kiota, an OpenAPI-based HTTP client and plugin manifest generator. In affected versions (1.25.1 to < 1.35.0), Kiota propagates the unvalidated `x-ai-capabilities.response_semantics.oauth_card_path` vendor extension directly into generated API plugin manifests, leading to potential path traversal exploitation by downstream consumers.

Alon Barad
Alon Barad
2 views•6 min read