{"id":"CVE-2026-27838","aliases":["GHSA-42cr-w2gr-m54q","PYSEC-2026-3418"],"url":"https://o3.security/vulnerability/CVE-2026-27838","summary":"wger: IDOR via user-unscoped cache keys on routine API actions exposes workout data","details":"wger is a free, open-source workout and fitness manager. Five routine detail action endpoints check a cache before calling `self.get_object()`. In versions up to and including 2.4, ache keys are scoped only by `pk` — no user ID is included. When a victim has previously accessed their routine via the API, an attacker can retrieve the cached response for the same PK without any ownership check. Commit e964328784e2ee2830a1991d69fadbce86ac9fbf contains a patch for the issue.","published":"2026-02-26T22:04:57.968Z","modified":"2026-08-07T11:50:50.631804223Z","cvss":{"score":3.1,"severity":"LOW","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"wger","fixedVersion":null}],"fix":{"url":"https://github.com/wger-project/wger/commit/e964328784e2ee2830a1991d69fadbce86ac9fbf","label":"wger-project/wger@e964328"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/27xxx/CVE-2026-27838.json"},{"type":"ADVISORY","url":"https://github.com/wger-project/wger/security/advisories/GHSA-42cr-w2gr-m54q"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-27838"},{"type":"FIX","url":"https://github.com/wger-project/wger/commit/e964328784e2ee2830a1991d69fadbce86ac9fbf"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T11:50:50.631804223Z"}}