PT-2026-82300 · Weblate · Weblate
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Weblate versions prior to 2026.7
Description
An authenticated user with project access can retrieve the change history of restricted components through nested API change endpoints. This occurs because these nested endpoints fail to apply the component-level access checks required for direct component views, allowing the enumeration of changes for hidden components. Exposed data may include the identity of the restricted component, translation and unit links, and change payload fields such as source or translated string content within the
target, old, and details values.Recommendations
Update to version 2026.7.
Exploit
Fix
Information Disclosure
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Weblate