PT-2026-82282 · Weblate · Weblate
CVSS v3.1
3.5
Low
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Weblate versions prior to 2026.8
Description
An authenticated user can modify the primary email of an account via PUT or PATCH requests to the '/api/users/{username}/' endpoint. Because the system fails to verify the new email address, a user can set it to an address they do not control, enabling them to accept subsequent team invitations sent to that address without having access to the recipient's mailbox.
Recommendations
Update to version 2026.8.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Weblate