A flaw has been found in wger-project wger up to 2.6.0-alpha2. This issue affects the function reset_user_password of the file wger/gym/views/gym.py of the component Password Reset. Executing a manipulation can lead to cross-site request forgery. It is possible to launch the attack remotely. This patch is called 3c6ce4b7f3eeafeb35318c6c4e82b1a3fd28b314. It is advisable to implement a patch to correct this issue.
CVE-2026-82544
Score 4.3 from GitHub Security Advisory published 2026-08-30. a secondary CVSS source baseline 4.3; sources differ by 0.0.
- Lower severity and no public exploit yet
An upstream fix is merged but not yet released — mitigate (WAF / firewall / segmentation) until the release ships, then apply it.
- CVSS v3
- 4.3
- EG Score
- 4.3MEDIUMhigh confidence
- EG Risk
- 19EG Risk 19/100
EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).
How it’s computedSeverity43% × 45%Exploitation0% × 40%Automatability0% × 15% - EPSS PROB
- 0.2%
- EPSS %ILE
- 13th
- KEV
- Not listed
Published
August 30, 2026
Last Modified
August 31, 2026
Advisory Details (4)
Auto-updated Aug 30, 2026GitHub - wger-project/wger: Self hosted FLOSS fitness/workout, nutrition and weight tracker · GitHub
https://github.com/wger-project/wger/commit 3c6ce4b7f3ee (wger-project/wger)
Fix landed in wger-project/wger commit 3c6ce4b7f3ee — awaiting tagged release
https://github.com/wger-project/wger/commit/3c6ce4b7f3eeafeb35318c6c4e82b1a3fd28b314Require POST for password reset and user (de)activation
Fix merged in wger-project/wger PR #2415 on 2026-07-09 — awaiting tagged release
https://github.com/wger-project/wger/pull/2415GET-based password reset and account deactivation can be triggered without CSRF protection · Issue #2380 · wger-project/wger · GitHub
https://github.com/wger-project/wger/issues/2380Vendor Advisories for CVE-2026-82544(1)
These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.
Weakness Classification(2)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Data Freshness Timeline
(refreshed 17× in last 7d / 77× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
- 2026-09-28 21:07 UTCEG score recompute
- 2026-09-28 21:07 UTCGHSA enrichment
- 2026-09-28 13:52 UTCEPSS rescore
- 2026-09-27 17:48 UTCEG score recompute
- 2026-09-27 17:48 UTCGHSA enrichment
- 2026-09-27 13:48 UTCEPSS rescore
- 2026-09-26 15:59 UTCEPSS rescore
- 2026-09-26 15:33 UTCEG score recompute
- 2026-09-26 15:32 UTCGHSA enrichment
- 2026-09-25 12:34 UTCEG score recompute
- 2026-09-25 12:34 UTCGHSA enrichment
- 2026-09-24 14:04 UTCEPSS rescore
- 2026-09-24 10:19 UTCEG score recompute
- 2026-09-24 10:19 UTCGHSA enrichment
- 2026-09-23 17:54 UTCEPSS rescore
- 2026-09-23 08:04 UTCEG score recompute
- 2026-09-23 08:04 UTCGHSA enrichment
- 2026-09-22 16:01 UTCEPSS rescore
- 2026-09-22 05:49 UTCEG score recompute
- 2026-09-22 05:49 UTCGHSA enrichment
- 2026-09-21 21:09 UTCEPSS rescore
- 2026-09-21 03:34 UTCEG score recompute
- 2026-09-21 03:34 UTCGHSA enrichment
- 2026-09-20 20:16 UTCEPSS rescore
- 2026-09-20 01:19 UTCEG score recompute
Show 55 moreShow fewer
- 2026-09-20 01:19 UTCGHSA enrichment
- 2026-09-18 23:04 UTCEG score recompute
- 2026-09-18 23:04 UTCGHSA enrichment
- 2026-09-18 19:28 UTCEPSS rescore
- 2026-09-17 20:49 UTCEG score recompute
- 2026-09-17 20:49 UTCGHSA enrichment
- 2026-09-16 15:38 UTCEG score recompute
- 2026-09-16 15:38 UTCGHSA enrichment
- 2026-09-16 14:08 UTCEPSS rescore
- 2026-09-16 05:15 UTCEPSS rescore
- 2026-09-15 13:08 UTCEG score recompute
- 2026-09-15 13:08 UTCGHSA enrichment
- 2026-09-15 03:12 UTCEPSS rescore
- 2026-09-15 03:12 UTCEPSS rescore
- 2026-09-14 10:53 UTCEG score recompute
- 2026-09-14 10:53 UTCGHSA enrichment
- 2026-09-13 08:38 UTCEG score recompute
- 2026-09-13 08:38 UTCGHSA enrichment
- 2026-09-12 06:23 UTCEG score recompute
- 2026-09-12 06:23 UTCGHSA enrichment
- 2026-09-11 04:08 UTCEG score recompute
- 2026-09-11 04:07 UTCGHSA enrichment
- 2026-09-10 01:52 UTCGHSA enrichment
- 2026-09-08 23:36 UTCEG score recompute
- 2026-09-08 23:36 UTCGHSA enrichment
- 2026-09-08 22:01 UTCEPSS rescore
- 2026-09-07 12:04 UTCEG score recompute
- 2026-09-07 12:03 UTCGHSA enrichment
- 2026-09-06 13:48 UTCEPSS rescore
- 2026-09-06 09:46 UTCEG score recompute
- 2026-09-06 09:46 UTCGHSA enrichment
- 2026-09-05 15:31 UTCEPSS rescore
- 2026-09-05 07:31 UTCEG score recompute
- 2026-09-05 07:31 UTCGHSA enrichment
- 2026-09-04 05:16 UTCEG score recompute
- 2026-09-04 05:15 UTCGHSA enrichment
- 2026-09-04 05:07 UTCEPSS rescore
- 2026-09-03 02:53 UTCEG score recompute
- 2026-09-03 02:53 UTCGHSA enrichment
- 2026-09-02 14:12 UTCEPSS rescore
- 2026-09-02 00:37 UTCEG score recompute
- 2026-09-02 00:37 UTCGHSA enrichment
- 2026-09-01 13:54 UTCEPSS rescore
- 2026-09-01 04:40 UTCEPSS rescore
- 2026-09-01 04:40 UTCEPSS rescore
- 2026-08-31 22:21 UTCEG score recompute
- 2026-08-31 22:21 UTCGHSA enrichment
- 2026-08-31 22:15 UTCEG score recompute
- 2026-08-31 22:15 UTCGHSA enrichment
- 2026-08-31 21:08 UTCGHSA enrichment
- 2026-08-31 16:51 UTCEG score recompute
- 2026-08-31 16:50 UTCGHSA enrichment
- 2026-08-30 14:32 UTCEG score recompute
- 2026-08-30 13:51 UTCEG score recompute
- 2026-08-30 13:49 UTCMITRE cvelistV5first tracked
Related CVEs(same CWE)
Frequently asked(5)
What is CVE-2026-82544?
When was CVE-2026-82544 disclosed?
Is CVE-2026-82544 actively exploited?
What is the CVSS score of CVE-2026-82544?
How do I remediate CVE-2026-82544?
Dependency Blast Radius
Explore the affected products and dependency analysis for CVE-2026-82544
Is Your Infrastructure Affected by CVE-2026-82544?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.