User Patching API Exposure in Weblate Localization Tool
CVE-2026-34393
8.8HIGH
What is CVE-2026-34393?
Weblate, a web-based localization tool, has a vulnerability in its user patching API endpoint that improperly restricts the scope of edits to user patches. This oversight allows unauthorized modifications, potentially compromising the integrity of localized content. The issue has been addressed in version 5.17, which enforces stricter access controls to mitigate risks and safeguard user data.
Affected Version(s)
weblate < 5.17
