A flaw has been found in wger-project wger up to 2.6.0-alpha2. This issue affects the function resetuserpassword of the file wger/gym/views/gym.py of the component Password Reset. Executing a manipulation can lead to cross-site request forgery. It is possible to launch the attack remotely. This patch is called 3c6ce4b7f3eeafeb35318c6c4e82b1a3fd28b314. It is advisable to implement a patch to correct this issue.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/82xxx/CVE-2026-82544.json",
"unresolved_ranges": [
{
"source": "AFFECTED_FIELD",
"extracted_events": [
{
"introduced": "2.6.0-alpha2"
},
{
"last_affected": "2.6.0-alpha2"
}
]
}
],
"cna_assigner": "VulDB",
"cwe_ids": [
"CWE-352",
"CWE-862"
]
}