<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T01:00:48.073498+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-40474</id>
    <title>CVE-2026-40474 — wger has Broken Access Control in the Global Gym Configuration Update Endpoint</title>
    <updated>2026-10-08T01:00:48.075287+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> wger-project wger</p>
<p>wger is a free, open-source workout and fitness manager. In versions 2.5 and below, the GymConfigUpdateView declares permission_required = 'config.change_gymconfig' but inherits WgerFormMixin instead of WgerPermissionMixin, so the permission is never enforced at runtime. Since GymConfig is an ownerless singleton, any authenticated user can modify the global gym configuration, triggering save() side effects that bulk-update user profile gym assignments — a vertical privilege escalation to installation-wide configuration control. This issue is fixed in version 2.5.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-40474"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-xppv-4jrx-qf8m</id>
    <title>GHSA-xppv-4jrx-qf8m — wger has Broken Access Control in Global Gym Configuration Update Endpoint</title>
    <updated>2026-10-08T01:00:48.075356+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: wger</p>
<p>## Summary</p>
<p>wger exposes a global configuration edit endpoint at `/config/gym-config/edit` implemented by `GymConfigUpdateView`. The view declares `permission_required = 'config.change_gymconfig'` but does not enforce it because it inherits `WgerFormMixin` (ownership-only checks) instead of the project’s permission-enforcing mixin (`WgerPermissionMixin`) .</p>
<p>The edited object is a singleton (`GymConfig(pk=1)`) and the model does not implement `get_owner_object()`, so `WgerFormMixin` skips ownership enforcement. As a result, a low-privileged authenticated user can modify installation-wide configuration and trigger server-side side effects in `GymConfig.save()`.</p>
<p>This is a vertical privilege escalation from a regular user to privileged global configuration control.
The application explicitly declares permission_required = 'config.change_gymconfig', demonstrating that the action is intended to be restricted; however, this requirement is never enforced at runtime.</p>
<p>## Affected endpoint</p>
<p>The config URLs map as follows.</p>
<p>File: `wger/config/urls.py`</p>
<p>```python
patterns_gym_config = [
    path('edit', gym_config.GymConfigUpdateView.as_view(), name='edit'),
]</p>
<p>urlpatterns = [
    path(
        'gym-config/',
        include((patterns_gym_config, 'gym_config'), namespace='gym_config'),
    ),
]
```</p>
<p>This resolves to:</p>
<p>`/config/gym-config/edit`</p>
<p>## Root cause</p>
<p>### The view declares a permission but does not enforce it</p>
<p>File: `wger/config/views/gym_config.py`</p>
<p>```python
class GymConfigUp…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-xppv-4jrx-qf8m"/>
  </entry>
</feed>
