User Patching API Exposure in Weblate Localization Tool
CVE-2026-34393

8.8HIGH

Key Information:

Vendor

Weblateorg

Status
Vendor
CVE Published:
15 April 2026

What is CVE-2026-34393?

Weblate, a web-based localization tool, has a vulnerability in its user patching API endpoint that improperly restricts the scope of edits to user patches. This oversight allows unauthorized modifications, potentially compromising the integrity of localized content. The issue has been addressed in version 5.17, which enforces stricter access controls to mitigate risks and safeguard user data.

Affected Version(s)

weblate < 5.17

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.