


Perceptive Security
SOC/SIEM Consultancy

Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, the REST API did not properly enforce…
Published:
26 augustus 2026 om 00:00:00
Alert date:
27 augustus 2026 om 00:01:16
Source:
nvd.nist.gov
Web Technologies, Identity & Access
CVE-2026-55228 affects Weblate, a web-based continuous localization platform for managing software translations. In versions prior to 2026.7, the REST API failed to properly enforce the scope of project- and workspace-scoped teams. This allowed authenticated users to submit invalid team configurations through the API, effectively assigning projects to teams without proper authorization checks. Exploiting this flaw could allow users to gain access to private projects they were not permitted to view or manage. The vulnerability could enable unauthorized translation, repository, and project-management operations beyond the user's intended permission scope. The issue has been resolved in Weblate version 2026.7, with a corresponding commit available on GitHub.
Technical details
Mitigation steps:
Affected products:
Weblate
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-55228
https://github.com/WeblateOrg/weblate/commit/19babc99b05f2cc299b5090f90f79d8181f25d79
https://github.com/WeblateOrg/weblate/security/advisories/GHSA-2q2q-jr9g-v9rf
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
