CVE-2026-27839Disclosure(wger / wger)

LOWCVSS 4.3 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

wger is a free, open-source workout and fitness manager. In versions up to and including 2.4, three `nutritional_values` action endpoints fetch objects via `Model.objects.get(pk=pk)` — a raw ORM call that bypasses the user-scoped queryset. Any authenticated user can read another user's private nutrition plan data, including caloric intake and full macro breakdown, by supplying an arbitrary PK. Commit 29876a1954fe959e4b58ef070170e81703dab60e contains a fix for the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-639

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • wger

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
wger

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-02-27: 3Technical Details · 2026-02-27: 202-27
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-27839 wger is a free, open-source workout and fitness manager. In versions up to and including 2.4, three `nutritional_values` action endpoints fetch objects via `Model.obj… https://www.cve.org/CVERecord?id=CVE-2026-27839

    Post summary

    The post announces CVE-2026-27839 in wger versions up to 2.4, noting that certain nutritional_values endpoints use Model.obj, but it provides no further technical or remediation details.

    00000146
    56.6K followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-27839: Lifting the Lid on wger: IDOR in the Nutrition API A classic Insecure Direct Object Reference (IDOR) vulnerability in the 'wger' workout manager allows authenticated users to access the nutritional plans of any other user. By bypassing... https://cvereports.com/reports/CVE-2026-27839

    Post summary

    The report discloses an IDOR vulnerability in the wger Nutrition API that permits authenticated users to view other users’ nutritional plans, but it provides no proof‑of‑concept, exploit code, active exploitation evidence, or patch information.

    0000043
    32 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-27839 Authenticated Nutrition Plan Data Disclosure in wger Fitness Manager Before 2.4 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27839

    Post summary

    A CVE-2026-27839 vulnerability in wger Fitness Manager (before version 2.4) permits authenticated users to disclose nutrition plan data, as reported by Vulmon.

    0000041
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwgerwger---

Explore more