CVE-2026-40474 is a privilege escalation vulnerability in wger (a free, open-source fitness management application) versions 2.5 and below. The GymConfigUpdateView fails to enforce required permissions at runtime due to inheriting from WgerFormMixin instead of WgerPermissionMixin, allowing any authenticated user to modify global gym configuration settings. This vulnerability has been patched in version 2.5. The vulnerability carries a HIGH severity rating (CVSS 7.6) with a low attack complexity requiring only network access and valid authentication credentials. Any authenticated user can exploit this to trigger bulk updates affecting user profile assignments across the entire installation, constituting a vertical privilege escalation to installation-wide configuration control. The attack has limited scope to integrity and availability impacts alongside minor confidentiality exposure. There is currently no evidence of active exploitation in the wild, with an extremely low EPSS score of 0.00013, indicating minimal probability of real-world exploitation. The vulnerability is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog, and it remains inactive on vulnerability hot lists. However, organizations running wger versions 2.5 or below should apply the available patch to eliminate this attack vector.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.5CPE matchmatch criteria | cpe:2.3:a:wger:wger:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.