PT-2026-82308 · Weblate · Weblate

·

CVE-2026-77507

·

Published

2026-08-26

·

Updated

2026-08-26

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Weblate versions prior to 2026.8
Description Object-scoped RSS feeds fail to apply standard permission checks, enabling unauthorized users to access change-history metadata from restricted components and private projects. In environments where anonymous access is enabled, this metadata can be retrieved without authentication. The exposed data includes project and component identities, contributor usernames and full names, action types, timestamps, and translation or unit links, although the actual content of translated strings is not disclosed.
Recommendations Update to version 2026.8.

Exploit

Fix

Missing Authorization

Incorrect Authorization

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77507
GHSA-VVC6-WVQM-W5GC

Affected Products

Weblate