CVE-2026-46437Medium· 4.8▾ Sunlitwger is a free, open-source workout and fitness manager. Versions prior to 2.6 have a vulnerability in the authentication/session lifecycle of `wger` where bearer-style API credentials remain valid after a user logs out and after a user …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 26.4 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
wger is a free, open-source workout and fitness manager. Versions prior to 2.6 have a vulnerability in the authentication/session lifecycle of wger where bearer-style API credentials remain valid after a user logs out and after a user changes their password. An attacker who steals a victim’s DRF authtoken (Authorization: Token ...) or JWT refresh token can continue to access protected /api/v2/* endpoints until the token is manually rotated/deleted (DRF token) or naturally expires (JWT refresh). Version 2.6 contains a patch.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
wger <= 2.1Connected by shared product, vendor, weakness, or advisory.
CVE-2026-46438Medium· 6.5wger is a free, open-source workout and fitness manager
CVE-2026-45161Medium· 5.4wger is a free, open-source workout and fitness manager
CVE-2026-46434High· 7.1wger is a free, open-source workout and fitness manager
CVE-2026-43976High· 7.1wger is a free, open-source workout and fitness manager
CVE-2026-86257Medium· 5.4wger before 2.6 fails to sanitize first_name and last_name fields in the gym member TSV export endpoint, allowing any gym member to inject spreadsheet formulas
CVE-2026-86256Medium· 5.4wger before 2.6 (affected versions <= 2.5.0) contains an open redirect vulnerability in the trainer_login view (wger/core/views/user.py)