PT-2026-82296 · Weblate · Weblate
CVE-2026-55227
·
Published
2026-08-26
·
Updated
2026-09-10
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Weblate versions prior to 2026.7
Description
Several endpoints perform object lookups using a global scope instead of restricting the search to projects the user is authorized to access. Consequently, the system returns an HTTP 403 (Forbidden) response instead of an HTTP 404 (Not Found) when a user requests an object they cannot see. This behavior allows unauthorized users to infer the existence of specific objects within private projects.
Recommendations
Update to version 2026.7.
Exploit
Fix
Side Channel Attack
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Weblate