CVE-2026-55228
published 2026-08-26CVE-2026-55228: Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, the REST API did not properly…
PriorityP348high8.1CVSS 3.1
AVNACLPRLUINSUCHIHAN
Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, the REST API did not properly enforce the scope of project- and workspace-scoped teams, allowing a user to submit invalid team configurations through the API. By assigning projects to a team via these unvalidated requests, a user could grant access to projects they were not authorized to see or manage. This could expose private projects and permit translation, repository, and project-management operations outside the user's intended permission scope. This issue is fixed in version 2026.7.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| weblate | weblate | >= 0 < 2026.7 | 2026.7 |
| weblateorg | weblate | < 2026.7 | 2026.7 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
ghsa·2026-08-28
CVE-2026-55228 [HIGH] CWE-639 Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
### Impact
The API did not properly handle project- and workspace-scoped teams and allowed setting invalid configurations, including granting access to projects the user has no access to.
### Patches
* https://github.com/WeblateOrg/weblate/pull/19970
### References
Parts of this issue were independently reported by four reporters:
* @H3xV0rT3x via GitHub
* [imhego](https://hackerone.com/imhego) via HackerOne
* [v01demort](https://hackerone.com/v01demort) via HackerOne
* [b4nder](https://hackerone.com/b4nder) via HackerOne
VulDB
WeblateOrg Weblate up to 2026.6 REST API privileges management
vuldb·2026-08-26·CVSS 8.1
CVE-2026-55228 [HIGH] WeblateOrg Weblate up to 2026.6 REST API privileges management
A vulnerability was found in WeblateOrg Weblate up to 2026.6. It has been declared as critical. This issue affects some unknown processing of the component REST API. The manipulation results in improper privilege management.
This vulnerability is reported as CVE-2026-55228. The attack can be launched remotely. No exploit exists.
It is recommended to upgrade the affected component.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-26
Published