CVE-2026-46437
Deferred Deferred - Pending Action

Authentication Token Persistence in wger Workout Manager

Vulnerability report for CVE-2026-46437, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: GitHub, Inc.

Description

wger is a free, open-source workout and fitness manager. Versions prior to 2.6 have a vulnerability in the authentication/session lifecycle of `wger` where bearer-style API credentials remain valid after a user logs out and after a user changes their password. An attacker who steals a victim’s DRF authtoken (`Authorization: Token ...`) or JWT refresh token can continue to access protected `/api/v2/*` endpoints until the token is manually rotated/deleted (DRF token) or naturally expires (JWT refresh). Version 2.6 contains a patch.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wger-project wger < 2.6

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CWE-613 According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in wger (versions before 2.6) allows API credentials like DRF authtokens or JWT refresh tokens to remain valid even after a user logs out or changes their password. Attackers who steal these tokens can continue accessing protected endpoints until tokens expire or are manually revoked.

Detection Guidance

Check for active API tokens in wger versions prior to 2.6 by inspecting the database for DRF authtokens or JWT refresh tokens. Look for tokens that remain valid after user logout or password changes. Use commands like 'sqlite3 wger.db "SELECT * FROM authtoken_token;"' to list DRF tokens or inspect JWT token tables if applicable.

Impact Analysis

Attackers can use stolen tokens to access your private workout data, perform unauthorized actions, or manipulate your account. This risks exposing sensitive information and compromising your fitness data integrity.

Compliance Impact

This vulnerability may violate data protection regulations like GDPR or HIPAA by allowing unauthorized access to personal health or fitness data. It undermines compliance with requirements for proper authentication and session management.

Mitigation Strategies

Upgrade wger to version 2.6 or later to patch the vulnerability. Manually rotate all existing API tokens (DRF authtokens and JWT refresh tokens) to ensure compromised tokens are invalidated. Review and delete any unused or suspicious tokens from the database.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-46437. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart