Access Control Issues in Weblate Localization Tool by Weblate
CVE-2026-33214

4.3MEDIUM

Key Information:

Vendor

Weblateorg

Status
Vendor
CVE Published:
15 April 2026

What is CVE-2026-33214?

Weblate, a widely-used web-based localization tool, has encountered an issue where its translation memory API inadvertently exposed endpoints without proper access control in versions prior to 5.17. This vulnerability could potentially allow unauthorized access to sensitive data. The issue has been addressed in version 5.17, which provides a necessary fix. Users who are unable to upgrade immediately can mitigate this risk by blocking access to the /api/memory/ endpoint on their HTTP server. For further details and updates, refer to the security advisory provided by Weblate.

Affected Version(s)

weblate < 5.17

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.