CVE-2026-33214
published 2026-04-15CVE-2026-33214: Weblate is a web based localization tool. In versions prior to 5.17, the translation memory API exposed unintended endpoints, which in turn didn't enforce…
PriorityP424medium4.3CVSS 3.1
AVNACLPRLUINSUCNILAN
EPSS
0.24%
14.9th percentile
Weblate is a web based localization tool. In versions prior to 5.17, the translation memory API exposed unintended endpoints, which in turn didn't enforce proper access control. This issue has been fixed in version 5.17. If users are unable to update immediately, they can work around this issue by blocking access to /api/memory/ in the HTTP server, which removes access to this feature.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| weblate | weblate | < 5.17 | 5.17 |
| weblate | weblate | >= 0 < 5.17 | 5.17 |
| weblateorg | weblate | < 5.17 | 5.17 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Weblate: Improper access control for the translation memory in API
ghsa·2026-04-16
CVE-2026-33214 [MEDIUM] CWE-862 Weblate: Improper access control for the translation memory in API
Weblate: Improper access control for the translation memory in API
### Impact
The translation memory API exposed unintended endpoints, which in turn didn't do proper access control.
### Patches
* https://github.com/WeblateOrg/weblate/pull/18513
### Workarounds
Blocking access to `/api/memory/` in the HTTP server removes access to this feature.
### References
This issue was reported by [ggamno](https://hackerone.com/ggamno) via HackerOne.
VulDB
weblate up to 5.16 Translation Memory API /api/memory/ authorization
vuldb·2026-04-15·CVSS 4.3
CVE-2026-33214 [MEDIUM] weblate up to 5.16 Translation Memory API /api/memory/ authorization
A vulnerability described as problematic has been identified in weblate up to 5.16. This issue affects some unknown processing of the file /api/memory/ of the component Translation Memory API. The manipulation results in missing authorization.
This vulnerability was named CVE-2026-33214. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is recommended.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-04-15
Published