PT-2026-82296 · Weblate · Weblate

CVE-2026-55227

·

Published

2026-08-26

·

Updated

2026-09-10

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Weblate versions prior to 2026.7
Description Several endpoints perform object lookups using a global scope instead of restricting the search to projects the user is authorized to access. Consequently, the system returns an HTTP 403 (Forbidden) response instead of an HTTP 404 (Not Found) when a user requests an object they cannot see. This behavior allows unauthorized users to infer the existence of specific objects within private projects.
Recommendations Update to version 2026.7.

Exploit

Fix

Side Channel Attack

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55227
GHSA-2P9G-X3CV-5HH4
PYSEC-2026-3941

Affected Products

Weblate