wger Privilege Escalation Vulnerability Allowing Unauthorized Access to Gym Management Functions

Vulnerability

A privilege escalation vulnerability has been identified in wger, a workout and fitness management application, affecting versions prior to 2.6. This vulnerability allows gym trainers to escalate their privileges to that of a gym manager or general manager by exploiting the trainer-login endpoint. The issue arises because the permission check can be bypassed after a trainer logs in as a lower-privileged user, enabling unauthorized access to sensitive gym administration capabilities, such as member data, contract management, and personal information of other trainers and managers.

Impact

Exploitation of this vulnerability allows any authenticated gym trainer to impersonate a gym manager or general gym manager, gaining full administrative access to gym management functions and data.

Reproduction

To reproduce this vulnerability, log in as a gym trainer with only 'gym.gym_trainer' permission. Then, use the trainer-login feature to switch into a low-privileged user, which will set the 'trainer.identity' session flag. This flag bypasses the permission check on subsequent trainer-login calls, allowing the trainer to access a manager account and its privileges.

Remediation

Users can update to wger version 2.6 or later, where this vulnerability has been fixed.

Added: Jul 17, 2026, 12:50 AM
Updated: Jul 17, 2026, 12:50 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
8.0
remediation
0.0
relevance
9.6
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.