CVE-2026-86256 | wger-project Wger up to 2.5.0 Impersonation wger/core/views/user.py trainer_login Next redirect

SecurityVulns

A vulnerability has been found in wger-project Wger up to 2.5.0 and classified as problematic. This affects the function trainer_login of the file wger/core/views/user.py of the component Impersonation. Performing a manipulation of the argument Next results in open redirect.

This vulnerability was named CVE-2026-86256. The attack may be initiated remotely. There is no available exploit.

The affected component should be upgraded.VulDB Recent EntriesRead More