CVE-2026-46438 | wger-project wger up to 2.5 Ownership Verification /api/v2/workoutlog WorkoutLogViewSet.get_owner_objects slot_entry authorization
A vulnerability described as problematic has been identified in wger-project wger up to 2.5. This vulnerability affects the function WorkoutLogViewSet.get_owner_objects of the file /api/v2/workoutlog of the component Ownership Verification. Executing a manipulation of the argument slot_entry can lead to authorization bypass.
This vulnerability is registered as CVE-2026-46438. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is recommended.VulDB Recent EntriesRead More