Listen to this Post
An authorization bypass vulnerability exists in wger Workout Manager due to flawed gym-scope checks across multiple gym management views. In wger/gym/views/user.py, wger/gym/views/admin_notes.py, wger/gym/views/document.py, wger/gym/views/contract.py, and wger/gym/views/user_config.py, access control relies on evaluating whether request.user.userprofile.gym != user.userprofile.gym. When both the requesting user (a trainer) and the target user have no assigned gym (gym = None), Python evaluates `None != None` as False. Consequently, the check silently passes, failing to raise an HttpResponseForbidden. The subsequent database query filters solely by `member_id` without secondary validation verifying if the requesting user shares a valid gym association with the target member. This flaw allows an authenticated user with delegated trainer permissions to read sensitive records—including private admin notes, uploaded documents, gym contracts, user configurations, and permission data—for any unassigned user on the instance.
DailyCVE Form:
Platform: wger Workout Manager
Version: Prior to 2.6
Vulnerability: Broken Access Control
Severity: High (CVSS 7.1)
date: May 12, 2026
Prediction: Patch released 2.6
What Undercode Say:
Analytics
The vulnerability stems from improper handling of `None` values in identity comparisons within Django views. When relying on relational attributes that can be null (None), standard inequality operators (!=) fail to enforce isolation if both entities lack an assignment.
Exploit: (Educational Purposes!)
The issue occurs when an authenticated trainer without a assigned gym (gym=None) sends GET requests to user-specific endpoints:
`GET /en/gym/notes/list/user/`
`GET /en/gym/documents/list/user/`
`GET /en/gym/contract/list/`
`GET /en/gym/user//config`
`GET /en/gym/user//permissions`
When targeting another user whose `gym` attribute is also None, the application processes the request and returns the requested member details due to the failed inequality guard.
Protection: from this CVE
To fix this vulnerability, upgrade wger to version 2.6 or later.
If updating immediately is not possible, modify the access check logic in `wger/gym/views/` to explicitly verify that `gym_id` is not `None` before comparing, and filter querysets by the requesting user’s gym ID:
Fixed implementation trainer_gym_id = request.user.userprofile.gym_id member_gym_id = user.userprofile.gym_id if trainer_gym_id is None or trainer_gym_id != member_gym_id: return HttpResponseForbidden() notes = AdminUserNote.objects.filter( member=member, member__userprofile__gym_id=request.user.userprofile.gym_id, )
Impact:
An authenticated attacker with trainer permissions can access private administrative notes, user contracts, uploaded documents, configuration details, and permission settings across all unassigned user accounts, leading to unauthorized data disclosure and privacy violation.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

