CVE-2026-86254 | wger-project wger up to master wger/core/views/user.py is_same_gym authorization (EUVD-2026-72110)
A vulnerability, which was classified as problematic, has been found in wger-project wger up to master. Affected by this vulnerability is the function is_same_gym of the file wger/core/views/user.py. This manipulation causes authorization bypass.
This vulnerability is handled as CVE-2026-86254. The attack can be initiated remotely. There is not any exploit available.