Impact
Weblate, a web-based continuous localization platform, allows teams to enforce two-factor authentication on its members before they receive team permissions. In versions before 2026.7, this enforcement is ignored for site-wide or global permissions. Consequently, a user who is part of a 2FA-enforced team but has not personally enabled 2FA can still be granted global permissions, including administrative access to the /manage/ interface. This represents an access-control flaw (CWE-284) that effectively elevates the user’s privileges beyond what the team policy intended.
Affected Systems
The vulnerability affects all installations of Weblate provided by WeblateOrg. The affected product is Weblate, and any release prior to 2026.7 is susceptible. No other vendors or product families are listed.
Risk and Exploitability
The CVSS score of 4.4 indicates low-to-moderate severity, and no EPSS score is available, suggesting that no publicly documented exploitation is known. The flaw is not listed in CISA’s KEV catalog, further implying limited or no active exploitation in the wild. Because the attack requires an existing account in a 2FA-enforced team that lacks 2FA, the threat vector is primarily internal; an insider or compromised local account could exploit the bypass. While the vulnerability does not allow arbitrary remote code execution, the ability to obtain global permissions can lead to significant damage, such as modifying configuration or translation data.
OpenCVE Enrichment