PT-2026-102639 · Weblate · Weblate

·

CVE-2026-86035

·

Published

2026-09-29

·

Updated

2026-09-29

CVSS v3.1

8.5

High

VectorAV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Weblate versions 4.11.1 through 2026.7.1
Description An argument-injection flaw exists in the Mercurial backend of this web-based continuous localization platform. Repository filenames starting with a hyphen (-) may be interpreted as Mercurial options rather than literal paths. An authenticated user possessing project-scoped component.edit permission can exploit this via a Mercurial-backed RESX component using the Update RESX files add-on. This could allow the execution of arbitrary commands with the privileges of the Weblate service account during a subsequent repository update.
Recommendations Update Weblate to version 2026.8.

Exploit

Fix

OS Command Injection

Argument Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-86035
GHSA-327H-QQGM-QV55

Affected Products

Weblate