PT-2026-94077 · Libretranslate+1 · Libretranslate

·

CVE-2026-92803

·

Published

2026-09-16

·

Updated

2026-09-16

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions LibreTranslate versions prior to 1.9.7
Description The download file route omits the access check decorator, which enables unauthenticated access to translated files. This allows attackers to bypass API key requirements and ignore ban lists to download files from protected instances.
Recommendations Update to version 1.9.7 or later. As a temporary workaround, restrict access to the download file route to minimize the risk of unauthorized file downloads.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92803

Affected Products

Libretranslate