CVE-2026-33212
published 2026-04-15CVE-2026-33212: Weblate is a web based localization tool. In versions prior to 5.17, the tasks API didn't verify user access for pending tasks. This could expose logs of…
PriorityP414low3.1CVSS 3.1
AVNACHPRLUINSUCLINAN
EPSS
0.22%
12.9th percentile
Weblate is a web based localization tool. In versions prior to 5.17, the tasks API didn't verify user access for pending tasks. This could expose logs of in-progress operations to users who don't have access to given scope. The attacker needs to brute-force the random UUID of the task, so exploiting this is unlikely with the default API rate limits. This issue has been fixed in version 5.17.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| weblate | weblate | < 5.17 | 5.17 |
| weblate | weblate | >= 0 < 5.17 | 5.17 |
| weblateorg | weblate | < 5.17 | 5.17 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Weblate: Improper access control for pending tasks in API
ghsa·2026-04-16
CVE-2026-33212 [LOW] CWE-284 Weblate: Improper access control for pending tasks in API
Weblate: Improper access control for pending tasks in API
### Impact
The API for tasks didn't verify user access for pending tasks. This could expose logs of in-progress operations to users who don't have access to given scope.
### Patches
* https://github.com/WeblateOrg/weblate/pull/18515
### Workarounds
The attacker needs to guess the random UUID of the task, so exploiting this is unlikely with the default API rate limits.
### References
This issue was identified by Michal Čihař.
VulDB
weblate up to 5.16 Tasks API access control
vuldb·2026-04-15·CVSS 3.1
CVE-2026-33212 [LOW] weblate up to 5.16 Tasks API access control
A vulnerability marked as critical has been reported in weblate up to 5.16. This vulnerability affects unknown code of the component Tasks API. The manipulation leads to improper access controls.
This vulnerability is uniquely identified as CVE-2026-33212. The attack is possible to be carried out remotely. No exploit exists.
It is suggested to upgrade the affected component.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-04-15
Published