
CVE-2026-43948 wger is a free, open-source workout and fitness manager. Prior to 2.6, the reset_user_password and gym_permissions_user_edit views in wger perform a gym-scope authori… https://www.cve.org/CVERecord?id=CVE-2026-43948
Post summary
The text announces CVE-2026‑43948, describing an authorization bypass in wger's reset_user_password and gym_permissions_user_edit views prior to v2.6, with no active exploitation, patch, or PoC disclosed.

