CVE-2026-46437: CWE-287: Improper Authentication in wger-project wger
Description
wger versions prior to 2.6 have an authentication vulnerability where bearer-style API tokens remain valid after user logout or password change. This allows an attacker who obtains a victim's DRF authtoken or JWT refresh token to continue accessing protected API endpoints until the token expires or is manually revoked. Version 2.6 includes a patch to address this issue.
CVSS v3.1
Score 4.8medium
Affected software
wger-project
wger
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
wger, an open-source workout and fitness manager, has an improper authentication vulnerability (CWE-287) affecting versions before 2.6. The issue lies in the session lifecycle management where bearer tokens such as DRF authtokens and JWT refresh tokens remain valid even after a user logs out or changes their password. This flaw allows continued access to protected API endpoints (/api/v2/*) by an attacker who has stolen these tokens. The vulnerability is patched in version 2.6.
Potential Impact
An attacker who steals a valid DRF authtoken or JWT refresh token can maintain unauthorized access to protected API endpoints until the token is manually revoked or naturally expires. This can lead to unauthorized information disclosure and limited integrity impact. The CVSS 3.1 base score is 4.8 (medium severity), reflecting network attack vector, high attack complexity, no privileges required, no user interaction, and limited confidentiality and integrity impact.
Mitigation Recommendations
Upgrade wger to version 2.6 or later, which contains a patch that properly invalidates bearer tokens upon user logout and password changes. Until upgrading, manually rotate or delete DRF authtokens and monitor token usage to reduce risk.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-05-13T22:18:22.830Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ac654e62cdf04f656564110
Added to database: 10/07/2026, 14:19:18 UTC
Last enriched: 10/07/2026, 14:33:28 UTC
Last updated: 10/07/2026, 14:33:28 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.