CVE-2026-55227
published 2026-08-26CVE-2026-55227: Weblate is a web-based localization tool. In versions prior to 2026.7, several endpoints look up objects in a globally scoped manner rather than restricting…
PriorityP423medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
EPSS
0.19%
9.3th percentile
Weblate is a web-based localization tool. In versions prior to 2026.7, several endpoints look up objects in a globally scoped manner rather than restricting the lookup to projects the user can access, so they return HTTP 403 (Forbidden) instead of 404 (Not Found) when a user requests an object they are not authorized to see. This difference lets unauthorized users infer whether a given object exists in a private Weblate project. The issue has been fixed in version 2026.7.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| weblate | weblate | >= 0 < 2026.7 | 2026.7 |
| weblateorg | weblate | < 2026.7 | 2026.7 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups
ghsa·2026-08-28
CVE-2026-55227 [MEDIUM] CWE-203 Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups
Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups
### Impact
The several endpoints could leak object existence information to users who had no access to it by HTTP status code 403 instead of 404.
### Patches
* https://github.com/WeblateOrg/weblate/pull/19971
### References
Thanks to Yaohui Wang for reporting this via GitHub.
VulDB
WeblateOrg Weblate up to 2026.6 improper authorization
vuldb·2026-08-26·CVSS 4.3
CVE-2026-55227 [MEDIUM] WeblateOrg Weblate up to 2026.6 improper authorization
A vulnerability has been found in WeblateOrg Weblate up to 2026.6 and classified as problematic. This issue affects some unknown processing. The manipulation leads to improper authorization.
This vulnerability is listed as CVE-2026-55227. The attack may be initiated remotely. There is no available exploit.
The affected component should be upgraded.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-26
Published