Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-g8gc-6c4h-jg86 | wger: IDOR in nutritional_values endpoints exposes private dietary data via direct ORM lookup |
Tue, 03 Mar 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 03 Mar 2026 01:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wger
Wger wger |
|
| CPEs | cpe:2.3:a:wger:wger:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Wger
Wger wger |
Fri, 27 Feb 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wger-project
Wger-project wger |
|
| Vendors & Products |
Wger-project
Wger-project wger |
Thu, 26 Feb 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | wger is a free, open-source workout and fitness manager. In versions up to and including 2.4, three `nutritional_values` action endpoints fetch objects via `Model.objects.get(pk=pk)` — a raw ORM call that bypasses the user-scoped queryset. Any authenticated user can read another user's private nutrition plan data, including caloric intake and full macro breakdown, by supplying an arbitrary PK. Commit 29876a1954fe959e4b58ef070170e81703dab60e contains a fix for the issue. | |
| Title | wger: IDOR in nutritional_values endpoints exposes private dietary data via direct ORM lookup | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-03T01:36:50.202Z
Reserved: 2026-02-24T02:32:39.801Z
Link: CVE-2026-27839
Updated: 2026-03-03T01:36:45.710Z
Status : Analyzed
Published: 2026-02-26T23:16:35.123
Modified: 2026-03-03T00:49:06.300
Link: CVE-2026-27839
No data.
OpenCVE Enrichment
Updated: 2026-04-16T16:00:13Z
Github GHSA