PT-2026-82300 · Weblate · Weblate

·

CVE-2026-62249

·

Published

2026-08-26

·

Updated

2026-08-26

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Weblate versions prior to 2026.7
Description An authenticated user with project access can retrieve the change history of restricted components through nested API change endpoints. This occurs because these nested endpoints fail to apply the component-level access checks required for direct component views, allowing the enumeration of changes for hidden components. Exposed data may include the identity of the restricted component, translation and unit links, and change payload fields such as source or translated string content within the target, old, and details values.
Recommendations Update to version 2026.7.

Exploit

Fix

Information Disclosure

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-62249
GHSA-92M8-WV36-PRMX

Affected Products

Weblate