AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-46437.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSMEDIUM / 0No severity score in this snapshot.
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSGitHub reviewed advisoryModified Oct 07, 2026

Disclosure summary

### Summary A vulnerability exists in the authentication/session lifecycle of `wger` where **bearer-style API credentials** remain valid **after a user logs out and after a user changes their password**. An attacker who steals a victim’s **DRF authtoken** (`Authorization: Token ...`) or **JWT refresh token** can continue to access protected `/api/v2/*` endpoints until the token is manually rotated/deleted (DRF token) or naturally expires (JWT refresh). lifecycle events do not revoke these credentials: - **Logout** (`/user/logout`) only clears the Django session cookie via `django_logout()` and does not revoke API tokens. - **Password change** updates the password hash, but does not revoke: - existing DRF tokens stored in `authtoken_token` - existing JWT refresh tokens (no server-side revocation list or token versioning); refresh can continue minting new access tokens until refresh expiry. #### Vulnerable Files - `wger/wger/core/views/user.py` (logout implementation) - `wger/settings/settings_global.py` (DRF auth configuration, SimpleJWT defaults) - `wger/settings/main.py` (commonly used production defaults for JWT lifetimes) - `wger/wger/utils/api_token.py` (authtoken rotation is m

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-v3x9-6gg8-c2c9

Open original source · Updated Oct 07, 2026

wger: API credentials remain valid after logout/password change

Source severity: MEDIUM / 0

EcosystemPackageAffected rangeFirst patched
pipwgerNot supplied

Original records & references

PUBLISHED 2026-10-07T09:59:10-04:00
MODIFIED 2026-10-07T09:59:11-04:00
INGESTED 2026-10-08T12:05:11-04:00