
CVE-2026-27839 wger is a free, open-source workout and fitness manager. In versions up to and including 2.4, three `nutritional_values` action endpoints fetch objects via `Model.obj… https://www.cve.org/CVERecord?id=CVE-2026-27839
Post summary
The post announces CVE-2026-27839 in wger versions up to 2.4, noting that certain nutritional_values endpoints use Model.obj, but it provides no further technical or remediation details.


