Access Control Issues in Weblate Localization Tool by Weblate
CVE-2026-33214
4.3MEDIUM
What is CVE-2026-33214?
Weblate, a widely-used web-based localization tool, has encountered an issue where its translation memory API inadvertently exposed endpoints without proper access control in versions prior to 5.17. This vulnerability could potentially allow unauthorized access to sensitive data. The issue has been addressed in version 5.17, which provides a necessary fix. Users who are unable to upgrade immediately can mitigate this risk by blocking access to the /api/memory/ endpoint on their HTTP server. For further details and updates, refer to the security advisory provided by Weblate.
Affected Version(s)
weblate < 5.17
