Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-46437— wger: API credentials remain valid after logout/password change

Quick assessment

Affected
wger-project wger
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

wger 是一款免费的、开源的运动和健身管理工具。在 wger 2.6 版本之前存在一个漏洞,涉及认证和会话生命周期的管理。具体而言,用户在注销或更改密码后,基于令牌(bearer-style)的 API 凭证仍然有效。如果攻击者窃取了受害者的 DRF 认证令牌(Authorization: Token ...)或 JWT 刷新令牌(JWT refresh token),他们可以在令牌被手动轮换/删除(DRF 令牌)或自然过期(JWT 刷新令牌)之前,继续访问受保护的 端点。wger 2.6 版本已包含对此漏洞的修

CVSS 4.8 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-46437

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
wger: API credentials remain valid after logout/password change
Source: CVE Program / CVE List V5
Vulnerability Description
wger is a free, open-source workout and fitness manager. Versions prior to 2.6 have a vulnerability in the authentication/session lifecycle of `wger` where bearer-style API credentials remain valid after a user logs out and after a user changes their password. An attacker who steals a victim’s DRF authtoken (`Authorization: Token ...`) or JWT refresh token can continue to access protected `/api/v2/*` endpoints until the token is manually rotated/deleted (DRF token) or naturally expires (JWT refresh). Version 2.6 contains a patch.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
认证机制不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
wger-project wger < 2.6 -

II. Public POCs for CVE-2026-46437

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-46437

请登录查看更多情报信息。

Other References for CVE-2026-46437 (2)

Same Patch Batch · wger-project · 2026-10-07 · 5 CVEs total

CVE-2026-43976 7.1 HIGH wger: cross-tenant admin notes/contracts leak via gym=None bypass (5 views)
CVE-2026-46434 7.1 HIGH wger: Trainer Privilege Escalation - Improper Privilege Management
CVE-2026-46438 6.5 MEDIUM wger: Cross-User Data Corruption via Missing Ownership Check on WorkoutLog.slot_entry
CVE-2026-45161 5.4 MEDIUM wger: trainer_login accepts GET - CSRF bypass enables forced session rebinding

IV. Related Vulnerabilities

V. Comments for CVE-2026-46437

No comments yet


Leave a comment