{"id":"CVE-2026-27838","summary":"wger: IDOR via user-unscoped cache keys on routine API actions exposes workout data","details":"wger is a free, open-source workout and fitness manager. Five routine detail action endpoints check a cache before calling `self.get_object()`. In versions up to and including 2.4, ache keys are scoped only by `pk` — no user ID is included. When a victim has previously accessed their routine via the API, an attacker can retrieve the cached response for the same PK without any ownership check. Commit e964328784e2ee2830a1991d69fadbce86ac9fbf contains a patch for the issue.","aliases":["GHSA-42cr-w2gr-m54q","PYSEC-2026-3418"],"modified":"2026-08-12T03:51:19.177608905Z","published":"2026-02-26T22:04:57.968Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/27xxx/CVE-2026-27838.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-639"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/27xxx/CVE-2026-27838.json"},{"type":"ADVISORY","url":"https://github.com/wger-project/wger/security/advisories/GHSA-42cr-w2gr-m54q"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-27838"},{"type":"FIX","url":"https://github.com/wger-project/wger/commit/e964328784e2ee2830a1991d69fadbce86ac9fbf"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/wger-project/wger","events":[{"introduced":"0"},{"fixed":"e964328784e2ee2830a1991d69fadbce86ac9fbf"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"2.4"}],"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:wger:wger:*:*:*:*:*:*:*:*"}}],"versions":["2.4","2.3","2.0","1.9","1.8","1.7","1.5","1.4","1.3","1.2","1.1","1.0.3","1.0.2","1.0.1","1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-27838.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"}]}