Access Control Flaw in Weblate Translation Memory API Exposes Unintended Endpoints
CVE-2026-33220

6.8MEDIUM

Key Information:

Vendor

Weblateorg

Status
Vendor
CVE Published:
15 April 2026

What is CVE-2026-33220?

Weblate is a web-based localization tool that, in versions prior to 5.17, had an access control issue within its translation memory API. This flaw allowed unintended access to specific endpoints, potentially exposing sensitive data. Users are encouraged to upgrade to version 5.17 or later to mitigate this issue. If immediate updating isn't feasible, users can opt to disable the affected feature, as the CDN add-on is not enabled by default. Detailed information regarding the fix can be found in the advisories provided.

Affected Version(s)

weblate < 5.17

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.