Improper API Scope Enforcement in Weblate by WeblateOrg
CVE-2026-55228
8.1HIGH
What is CVE-2026-55228?
Weblate, a web-based continuous localization platform, suffers from an improper API scope enforcement issue. This vulnerability allows unauthorized users to submit invalid configurations through the REST API, potentially granting access to projects they should not be permitted to see or manage. Consequently, this could lead to the exposure of private projects and unauthorized operations related to translation, repositories, and project management. The issue has been resolved in Weblate version 2026.7.
Affected Version(s)
weblate < 2026.7
