PT-2026-82282 · Weblate · Weblate

·

CVE-2026-77508

·

Published

2026-08-26

·

Updated

2026-08-26

CVSS v3.1

3.5

Low

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Weblate versions prior to 2026.8
Description An authenticated user can modify the primary email of an account via PUT or PATCH requests to the '/api/users/{username}/' endpoint. Because the system fails to verify the new email address, a user can set it to an address they do not control, enabling them to accept subsequent team invitations sent to that address without having access to the recipient's mailbox.
Recommendations Update to version 2026.8.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77508
GHSA-X84P-6892-473C

Affected Products

Weblate