Weblate · Weblate · CVE-2026-77508
**Name of the Vulnerable Software and Affected Versions**
Weblate versions prior to 2026.8
**Description**
An authenticated user can modify the primary email of an account via PUT or PATCH requests to the '/api/users/{username}/' endpoint. Because the system fails to verify the new email address, a user can set it to an address they do not control, enabling them to accept subsequent team invitations sent to that address without having access to the recipient's mailbox.
**Recommendations**
Update to version 2026.8.