PatchSiren cyber security CVE debrief
CVE-2026-45161 wger-project CVE debrief
The CVE-2026-45161 vulnerability in wger, a free, open-source workout and fitness manager, allows an attacker to bypass CSRF protection on the `trainer_login` view by accepting GET requests. This enables forced session rebinding, potentially allowing an attacker to bind a trainer's session to an arbitrary user account. The issue is fixed in version 2.6.
- Vendor
- wger-project
- Product
- wger
- CVSS
- MEDIUM 5.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-07
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-07
- Advisory updated
- 2026-10-07
Who should care
Defenders responsible for wger applications, particularly those using versions less than 2.6, should assess exposure and apply the fix to prevent session rebinding attacks. This includes verifying wger versions and configurations, reviewing and updating configurations to ensure CSRF protection is enabled, and monitoring for suspicious activity. Additionally, security teams and vulnerability management teams should be aware of the potential impact and take
Why it matters
CVE-2026-45161 allows an attacker to bypass CSRF protection in wger, enabling forced session rebinding. Defenders should verify exposure, apply the fix, and monitor for suspicious activity.
- Session rebinding could allow attackers to impersonate trainers.
- Defenders need to verify exposure and apply the fix to prevent exploitation.
- The vulnerability requires verification of wger versions and configurations.
Technical summary
The `trainer_login` view in wger accepts GET requests and executes `django_login()` without CSRF protection. An attacker can exploit this by embedding an `<img>` tag on a malicious page, causing an authenticated trainer's browser to auto-issue a GET request with their session cookie, effectively rebinding their session to an arbitrary user account. This issue allows for session rebinding, potentially enabling an attacker to impersonate trainers. The vulnerability requires verification of wger versions and configurations to ensure CSRF protection is enabled.
Defensive priority
Defenders should prioritize verifying exposure and applying the fix, as the vulnerability allows for session rebinding.
Recommended defensive actions
- Verify if the wger application is using a version less than 2.6 and update to 2.6 or later.
- Review and update configurations to ensure CSRF protection is enabled for the `trainer_login` view.
- Monitor for suspicious activity related to session binding and user account management.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
Evidence notes
The CVE record and source item provide details on the vulnerability, its impact, and the fix in version 2.6. Defenders should verify exposure by checking wger versions and configurations, review and update configurations to ensure CSRF protection is enabled for the `trainer_login` view, and monitor for suspicious activity related to session binding and user account management. Evidence is limited to public CVE details and source item descriptions. No additional information is available without further investigation.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-45161 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-45161
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-45161 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-45161
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
wger: trainer_login accepts GET - CSRF bypass enables forced session rebinding
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/45xxx/CVE-2026-45161.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/wger-project/wger/security/advisories/GHSA-xf64-4pmc-h8qf
Supplemental source - x_refsource_CONFIRM
-
Source reference
Unverified legacy reference
URL: https://github.com/wger-project/wger/releases/tag/2.6
Supplemental source - x_refsource_MISC
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.