Impact
The vulnerability resides in the REST API of Weblate versions prior to 2026.7, where the server failed to enforce project‑ and workspace‑scoped team boundaries. An authenticated project manager can submit malformed team configuration requests that assign any project to a team. By doing so, the attacker effectively grants themselves read and management permissions to private projects that should not be visible, enabling unauthorized translation, repository and project‑management operations. This results in information disclosure and potential disruption of project controls.
Affected Systems
Weblate, the web‑based continuous localization platform from WeblateOrg, is affected. All installations running a version earlier than 2026.7 are vulnerable, regardless of deployment mode. The vulnerability was discovered through a commit that affected the project's REST API logic.
Risk and Exploitability
The CVSS score of 8.1 categorizes this flaw as high severity, and although its EPSS score is not listed, the lack of a KEV listing suggests the vulnerability has not yet been widely exploited. The known attack path requires legitimate authentication to a role such as project manager; from there the attacker exploits the API to alter team assignments. Because the flaw leverages internal API calls and does not require elevated privileges beyond those granted to the target role, the likelihood of exploitation depends on an attacker’s ability to gain authenticated access to the system.
OpenCVE Enrichment