AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-46438.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSMEDIUM / 0No severity score in this snapshot.
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSGitHub reviewed advisoryModified Oct 07, 2026

Disclosure summary

### Summary An authenticated attacker can inject arbitrary workout log entries into any other user's `SlotEntry` by supplying the victim's `slot_entry` ID in a `POST /api/v2/workoutlog/` request. The `slot_entry` foreign key is not included in the ownership verification performed by `WorkoutLogViewSet.get_owner_objects()`, so the server accepts and persists the cross-user reference without error. Because `SlotEntry.get_config_data()` retrieves associated logs via `self.workoutlog_set.all()` with **no user filter**, the attacker's injected data is silently folded into the victim's progressive-overload calculations, corrupting their auto-generated weight and repetition targets. ### Details wger uses a centralized ownership-verification pattern in `WgerOwnerObjectModelViewSet.create()` (file: `wger/utils/viewsets.py`). This method iterates over the list returned by each ViewSet's `get_owner_objects()` and verifies that every listed foreign-key value in the request belongs to the authenticated user. **Foreign keys not present in the list are never checked.** `WorkoutLogViewSet.get_owner_objects()` returns: ```python # File: wger/manager/api/views.py, lines 312-316 def get_owner_objects

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-rjpf-7pf5-q54x

Open original source · Updated Oct 07, 2026

wger: Cross-User Data Corruption via Missing Ownership Check on WorkoutLog.slot_entry

Source severity: MEDIUM / 0

EcosystemPackageAffected rangeFirst patched
pipwgerNot supplied

Original records & references

PUBLISHED 2026-10-07T09:59:17-04:00
MODIFIED 2026-10-07T09:59:18-04:00
INGESTED 2026-10-08T12:05:11-04:00