Account Email Modification Vulnerability in Weblate Localization Tool
CVE-2026-77508

3.5LOW

Key Information:

Vendor

Weblateorg

Status
Vendor
CVE Published:
26 August 2026

What is CVE-2026-77508?

Weblate, a web-based localization tool, contains a vulnerability that permits authenticated users to modify an account's primary email address without proper verification. This flaw enables an attacker to initiate a later invitation to a different team member for that email, allowing access without confirmation from the intended recipient’s mailbox. The issue presents risks associated with unauthorized access and information disclosure, highlighting the importance of ensuring thorough validation measures are implemented. The vulnerability has been addressed in Weblate version 2026.8.

Affected Version(s)

weblate < 2026.8

References

CVSS V3.1

Score:
3.5
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.