PT-2026-82308 · Weblate · Weblate
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Weblate versions prior to 2026.8
Description
Object-scoped RSS feeds fail to apply standard permission checks, enabling unauthorized users to access change-history metadata from restricted components and private projects. In environments where anonymous access is enabled, this metadata can be retrieved without authentication. The exposed data includes project and component identities, contributor usernames and full names, action types, timestamps, and translation or unit links, although the actual content of translated strings is not disclosed.
Recommendations
Update to version 2026.8.
Exploit
Fix
Missing Authorization
Incorrect Authorization
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Weblate