PT-2026-22201 · Weblate · Weblate

·

CVE-2026-27457

·

Published

2026-02-26

·

Updated

2026-03-09

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Weblate versions prior to 5.16.1
Description Weblate’s REST API AddonViewSet in weblate/api/views.py (line 2831) did not properly restrict access to addon information based on user permissions. Specifically, the queryset = Addon.objects.all() assignment within the viewset allowed any authenticated user, or even anonymous users if REQUIRE LOGIN was not enabled, to list all addons across all projects and components using the GET /api/addons/ and GET /api/addons/{id}/ API endpoints. This allowed unauthorized access to addon configurations.
Recommendations Update to Weblate version 5.16.1 or later.

Exploit

Fix

Information Disclosure

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-27457
GHSA-WPPC-7CQ7-CGFV
OPENSUSE-SU-2026:10309-1
PYSEC-2026-2310

Affected Products

Weblate