{"id":"CVE-2026-43976","summary":"wger: cross-tenant admin notes/contracts leak via gym=None bypass (5 views)","details":"wger is a free, open-source workout and fitness manager. Prior to version 2.6, five gym management views in wger apply a flawed gym-scope guard (`gym_a != gym_b`) that silently passes when both operands are `None`. A trainer with `gym.gym_trainer` and `gym.add_adminusernote` permissions and no gym assignment (`gym=None`) can read private admin notes, uploaded documents, gym contracts, user configuration, and user permission data for **any other unaffiliated user** on the instance. The subsequent querysets filter only on the attacker-supplied `member_id` with no secondary gym-scoped validation, so all records are disclosed. Version 2.6 fixes the issue.","aliases":["GHSA-c72h-82w6-rqfp"],"modified":"2026-10-09T02:49:23.612721515Z","published":"2026-10-07T13:33:11.008Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-863"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/43xxx/CVE-2026-43976.json"},"references":[{"type":"WEB","url":"https://github.com/wger-project/wger/releases/tag/2.6"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/43xxx/CVE-2026-43976.json"},{"type":"ADVISORY","url":"https://github.com/wger-project/wger/security/advisories/GHSA-c72h-82w6-rqfp"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-43976"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/wger-project/wger","events":[{"introduced":"0"},{"fixed":"e1d70bcc38cd56ae4a254dca1713c404d069f319"}],"database_specific":{"source":["AFFECTED_FIELD","REFERENCES"],"extracted_events":[{"introduced":"0"},{"fixed":"2.6"}]}}],"versions":["2.5","2.4","2.3","2.0","1.9","1.8","1.7","1.5","1.4","1.3","1.2","1.1","1.0.3","1.0.2","1.0.1","1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-43976.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"}]}