Oct 7, 2026·5 min read·7 visits
Missing validation in wger's API endpoints allows authenticated users to inject unauthorized training logs into any user's workout schedule by referencing their slot_entry ID, corrupting dynamic progressive-overload configurations.
CVE-2026-46438 is a critical Broken Object Level Authorization (BOLA) / Insecure Direct Object Reference (IDOR) vulnerability identified in the wger fitness manager prior to version 2.6. An authenticated attacker can exploit a missing authorization check on the slot_entry API parameter to inject unauthorized workout logs into another user's training schedule. This results in the corruption of the target user's automated progressive-overload calculations.
The open-source fitness manager wger exposes standard REST API endpoints to facilitate the tracking of workouts, routines, and user logs. Within its multi-tenant architecture, isolation is enforced at the controller level to prevent cross-user data interference.
In versions prior to 2.6, the api validation layer failed to enforce appropriate object-level authorization on several relational fields. Specifically, the model controller representing workout logs neglected to map parent-child relationships for the slot_entry entity.
Consequently, an authenticated user could issue requests containing database identifiers referencing assets owned by unrelated accounts. The backend accepted and committed these associations, breaking logical boundaries between tenants and enabling unauthorized state modification.
The Django REST Framework integration in wger uses a custom superclass named WgerOwnerObjectModelViewSet to automate owner-based authorization checks during model creation and modification. This controller interceptor evaluates properties provided in the API request against a registration list returned by get_owner_objects().
Prior to the implementation of the security patch, the WorkoutLogViewSet class in wger/manager/api/views.py only evaluated Routine and WorkoutSession fields for ownership validation. The slot_entry parameter, which links a specific log entry to a scheduled slot, was omitted from the list.
Because of this omission, when an authenticated client submitted a POST request containing a foreign slot_entry identifier, the system only validated ownership of the auxiliary routine identifier. The database saved the record, creating an Insecure Direct Object Reference (IDOR) state.
A secondary failure point exists in the query logic of the calculation engine located in wger/manager/models/slot_entry.py. The SlotEntry.get_config_data() method loaded all logs connected to the slot entry without validating their ownership. This design defect allowed the attacker's unauthorized records to pollute the automated training statistics generation pipeline.
To understand the technical changes, we examine the diff from the security patch applied to the code repository. The primary vulnerability resided in the registration parameters of the REST API controller.
# Vulnerable configuration in wger/manager/api/views.py
class WorkoutLogViewSet(WgerOwnerObjectModelViewSet):
def get_owner_objects(self):
return [(Routine, 'routine'), (WorkoutSession, 'session')]The patched viewset updates the return value of get_owner_objects to enforce validation checks against both the slot_entry and the recursive next_log fields.
# Patched configuration in wger/manager/api/views.py
class WorkoutLogViewSet(WgerOwnerObjectModelViewSet):
def get_owner_objects(self):
return [
(Routine, 'routine'),
(WorkoutSession, 'session'),
(SlotEntry, 'slot_entry'),
(WorkoutLog, 'next_log'),
]Furthermore, model-level security guarantees were added within the database persistence interface in wger/manager/models/log.py. This ensures that even if API controllers are bypassed, direct model updates fail authorization validation.
# Patched validation in wger/manager/models/log.py
def save(self, *args, **kwargs):
if self.routine and self.routine.user != self.user:
return
if self.slot_entry and self.slot_entry.slot.day.routine.user != self.user:
returnAn attacker requires a valid authenticated session to exploit this vulnerability. The vulnerability requires no administrative privileges and can be triggered using a standard client connection.
The attack process initiates with sequential scanning of integer identifiers associated with targeted slot_entry objects. Because these identifiers are auto-incrementing, discovery is straightforward.
Upon identifying a target identifier, the attacker constructs a POST payload specifying a legitimate routine identifier owned by the attacker alongside the target slot_entry identifier owned by the victim. The application server processes the request, bypasses checking on the slot_entry property, and logs the malicious telemetry.
The primary impact of this vulnerability is unauthorized data manipulation and integrity corruption within user profiles. Because wger automates progress tracking via calculation engines, the presence of unauthorized workout logs corrupts the statistical baseline of the targeted athlete.
Specifically, the progressive-overload scheduling module relies on historical weight and repetition limits to project upcoming goals. Injecting extreme or incorrect values forces the application to calculate unreachable targets, impairing the usability of the software.
While the vulnerability does not lead directly to arbitrary code execution or data extraction, the complete loss of multi-tenant integrity across relational workout records introduces a significant trust barrier in shared deployments.
The primary remediation mechanism is the installation of wger version 2.6. This release closes the authorization gap in the API controllers and enforces defensive validation constraints inside the underlying models.
For system administrators who cannot perform immediate platform updates, temporary relief is achievable by auditing database transactions and filtering suspicious logs. Running targeted database queries can expose instances where log records point to incompatible parent accounts.
Additionally, Web Application Firewalls (WAF) can be configured to block suspicious requests directed at the API endpoint. Inspecting incoming request bodies for mismatching parameters helps reduce the potential attack surface.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N| Product | Affected Versions | Fixed Version |
|---|---|---|
wger wger-project | < 2.6 | 2.6 |
| Attribute | Detail |
|---|---|
| CWE ID | CWE-862 (Missing Authorization) |
| Attack Vector | Network |
| CVSS v3.1 | 6.5 (Medium) |
| Exploit Status | Proof of Concept (PoC) available |
| Remediation | Official upgrade path to version 2.6 |
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
A critical remote code execution vulnerability was identified in WeasyPrint prior to version 70.0. When compiling HTML containing a malicious Encapsulated PostScript (EPS) graphic on a host with Ghostscript installed, Pillow invokes Ghostscript to process the image, executing arbitrary PostScript commands.
An authorization bypass vulnerability in the Spotify Backstage TechDocs backend plugin allows authenticated attackers with access to at least one valid TechDocs site to read arbitrary static documentation from other entities. This occurs due to un-sanitized relative subpaths passing directly to external storage drivers.
The @backstage/plugin-scaffolder-backend package prior to version 4.1.0 is vulnerable to sensitive information exposure in Scaffolder task failure events. Under specific template and failure conditions, an authenticated user can retrieve backend-managed credentials, such as VCS access tokens and API keys, from affected task execution events and stored database logs. This vulnerability has been remediated in version 4.1.0 of the package and is bundled with the Backstage platform release v1.54.6.
A critical security flaw exists in PraisonAI before version 4.6.78 when operating in AgentMail webhook mode. The application processes incoming POST requests without checking for cryptographic signatures, allowing unauthenticated attackers to forge emails, spoof identities, and force AI agents to execute unauthorized operations.
A missing authorization vulnerability (CWE-862) exists in praisonai-platform versions prior to 0.1.9, allowing low-privileged workspace members to delete planning dependencies on issues owned by administrators by routing the deletion request through an attacker-owned issue.
CVE-2026-105795 (GHSA-6gw6-rv2g-25mg) is a critical path traversal vulnerability in Microsoft Kiota, an OpenAPI-based HTTP client and plugin manifest generator. In affected versions (1.25.1 to < 1.35.0), Kiota propagates the unvalidated `x-ai-capabilities.response_semantics.oauth_card_path` vendor extension directly into generated API plugin manifests, leading to potential path traversal exploitation by downstream consumers.