Weblate · Weblate · CVE-2026-77507
**Name of the Vulnerable Software and Affected Versions**
Weblate versions prior to 2026.8
**Description**
Object-scoped RSS feeds fail to apply standard permission checks, enabling unauthorized users to access change-history metadata from restricted components and private projects. In environments where anonymous access is enabled, this metadata can be retrieved without authentication. The exposed data includes project and component identities, contributor usernames and full names, action types, timestamps, and translation or unit links, although the actual content of translated strings is not disclosed.
**Recommendations**
Update to version 2026.8.