Unauthenticated Access Issue in LibreTranslate Product
CVE-2026-92803
6.9MEDIUM
What is CVE-2026-92803?
LibreTranslate version 1.9.6 is vulnerable due to the omission of the access_check decorator from the download_file route. This flaw permits unauthenticated users to access translated files, allowing potential attackers to bypass API key requirements and exploit ban lists. As a result, sensitive files can be downloaded without proper authentication on instances intended to be secured.
Affected Version(s)
LibreTranslate 0 <= 1.9.6
