Security Flaw in Weblate Localization Platform Allows Global Permission Bypass
CVE-2026-61790

4.4MEDIUM

Key Information:

Vendor

Weblateorg

Status
Vendor
CVE Published:
26 August 2026

What is CVE-2026-61790?

A significant vulnerability in Weblate allows users to bypass two-factor authentication (2FA) when obtaining site-wide global permissions. While teams can enforce 2FA for their members, this requirement does not apply globally, potentially exposing sensitive site management functions. As of versions prior to 2026.7, users who belong to teams enforcing 2FA can still gain global access without properly configuring 2FA. This flaw impacts the effectiveness of security measures, enabling unauthorized actions on the site management interface. This issue has been addressed in version 2026.7.

Affected Version(s)

weblate < 2026.7

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.