Weblate · Weblate · CVE-2026-55228
**Name of the Vulnerable Software and Affected Versions**
Weblate versions prior to 2026.7
**Description**
The REST API fails to properly enforce the scope of project- and workspace-scoped teams. This allows a user to submit invalid team configurations, enabling them to assign projects to a team via unvalidated requests. Consequently, a user could grant themselves access to projects they are not authorized to see or manage, potentially exposing private projects and allowing unauthorized translation, repository, and project-management operations.
**Recommendations**
Update to version 2026.7.