CVE-2026-34393
published 2026-04-15CVE-2026-34393: Weblate is a web based localization tool. In versions prior to 5.17, the user patching API endpoint didn't properly limit the scope of edits. This issue has…
PriorityP356high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.54%
43.0th percentile
Weblate is a web based localization tool. In versions prior to 5.17, the user patching API endpoint didn't properly limit the scope of edits. This issue has been fixed in version 5.17.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| weblate | weblate | < 5.17 | 5.17 |
| weblate | weblate | >= 0 < 5.17 | 5.17 |
| weblateorg | weblate | < 5.17 | 5.17 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
weblate up to 5.16 API Endpoint privileges management (GHSA-3382-gw9x-477v)
vuldb·2026-04-16·CVSS 8.8
CVE-2026-34393 [HIGH] weblate up to 5.16 API Endpoint privileges management (GHSA-3382-gw9x-477v)
A vulnerability marked as critical has been reported in weblate up to 5.16. Affected by this issue is some unknown functionality of the component API Endpoint. The manipulation leads to improper privilege management.
This vulnerability is traded as CVE-2026-34393. It is possible to initiate the attack remotely. There is no exploit available.
It is suggested to upgrade the affected component.
GHSA
Weblate: Privilege escalation in the user API endpoint
ghsa·2026-04-16
CVE-2026-34393 [HIGH] CWE-269 Weblate: Privilege escalation in the user API endpoint
Weblate: Privilege escalation in the user API endpoint
### Impact
The user patching API endpoint didn't properly limit the scope of edits.
### Patches
* https://github.com/WeblateOrg/weblate/pull/18687
### References
Thanks to @tikket1 and @DavidCarliez for reporting this via GitHub. We received two individual reports for this.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-04-15
Published