top of page
perceptive_background_267k.jpg

Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, the REST API did not properly enforce…

Published:

26 augustus 2026 om 00:00:00

Alert date:

27 augustus 2026 om 00:01:16

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Identity & Access

CVE-2026-55228 affects Weblate, a web-based continuous localization platform for managing software translations. In versions prior to 2026.7, the REST API failed to properly enforce the scope of project- and workspace-scoped teams. This allowed authenticated users to submit invalid team configurations through the API, effectively assigning projects to teams without proper authorization checks. Exploiting this flaw could allow users to gain access to private projects they were not permitted to view or manage. The vulnerability could enable unauthorized translation, repository, and project-management operations beyond the user's intended permission scope. The issue has been resolved in Weblate version 2026.7, with a corresponding commit available on GitHub.

Technical details

Mitigation steps:

Affected products:

Weblate

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page