CVE-2026-46437: Wger-Project Wger
Medium severity, CVSS 4.8. EPSS: 0.2% chance of exploitation in the next 30 days.
wger is a free, open-source workout and fitness manager. Versions prior to 2.6 have a vulnerability in the authentication/session lifecycle of `wger` where bearer-style API credentials remain valid after a user logs out and after a user changes their password. An attacker who steals a victim’s DRF authtoken (`Authorization: Token ...`) or JWT refresh token can continue to access protected `/api/v2/*` endpoints until the token is manually rotated/deleted (DRF token) or naturally expires (JWT refresh). Version 2.6 contains a patch.
Affected products
- Wger-Project Wger: before 2.6 (fixed in 2.6)
Published 2026-10-07. Last modified 2026-10-10.