Account Email Modification Vulnerability in Weblate Localization Tool
CVE-2026-77508
3.5LOW
What is CVE-2026-77508?
Weblate, a web-based localization tool, contains a vulnerability that permits authenticated users to modify an account's primary email address without proper verification. This flaw enables an attacker to initiate a later invitation to a different team member for that email, allowing access without confirmation from the intended recipient’s mailbox. The issue presents risks associated with unauthorized access and information disclosure, highlighting the importance of ensuring thorough validation measures are implemented. The vulnerability has been addressed in Weblate version 2026.8.
Affected Version(s)
weblate < 2026.8
