
CVE-2026-40474 wger is a free, open-source workout and fitness manager. In versions 2.5 and below, the GymConfigUpdateView declares permission_required = 'config.change_gymconfig' b… https://www.cve.org/CVERecord?id=CVE-2026-40474
Post summary
The CVE points to a missing permissions check in wger’s GymConfigUpdateView for older versions; no PoC or active exploitation is mentioned.

