Description
Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, a team can require its members to configure two-factor authentication before receiving the team's permissions, but this requirement is not enforced for site-wide global permissions. As a result, a user who belongs to a team that enforces 2FA and grants a global permission still receives that global permission even without 2FA configured, while the same requirement is correctly applied to project-, component-, and workspace-scoped permissions. Such a user can act on the granted global permission, including reaching the site management interface at /manage/. This issue is fixed in version 2026.7.
Published: 2026-08-26
Score: 4.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation via 2FA bypass for site-wide permissions
Action: Immediate Patch
AI Analysis

Impact

Weblate, a web-based continuous localization platform, allows teams to enforce two-factor authentication on its members before they receive team permissions. In versions before 2026.7, this enforcement is ignored for site-wide or global permissions. Consequently, a user who is part of a 2FA-enforced team but has not personally enabled 2FA can still be granted global permissions, including administrative access to the /manage/ interface. This represents an access-control flaw (CWE-284) that effectively elevates the user’s privileges beyond what the team policy intended.

Affected Systems

The vulnerability affects all installations of Weblate provided by WeblateOrg. The affected product is Weblate, and any release prior to 2026.7 is susceptible. No other vendors or product families are listed.

Risk and Exploitability

The CVSS score of 4.4 indicates low-to-moderate severity, and no EPSS score is available, suggesting that no publicly documented exploitation is known. The flaw is not listed in CISA’s KEV catalog, further implying limited or no active exploitation in the wild. Because the attack requires an existing account in a 2FA-enforced team that lacks 2FA, the threat vector is primarily internal; an insider or compromised local account could exploit the bypass. While the vulnerability does not allow arbitrary remote code execution, the ability to obtain global permissions can lead to significant damage, such as modifying configuration or translation data.

Generated by OpenCVE AI on August 26, 2026 at 22:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Weblate 2026.7 or later, which implements the fix.
  • If an immediate upgrade is not possible, remove or re‑assign all global permissions from users who do not have 2FA enabled, ensuring that the 2FA requirement is respected for site-wide access.
  • Conduct an audit of current users to confirm that no team member lacking 2FA holds global permissions, and remove any found to maintain compliance.

Generated by OpenCVE AI on August 26, 2026 at 22:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Weblate
Weblate weblate
Vendors & Products Weblate
Weblate weblate

Thu, 27 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Description Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, a team can require its members to configure two-factor authentication before receiving the team's permissions, but this requirement is not enforced for site-wide global permissions. As a result, a user who belongs to a team that enforces 2FA and grants a global permission still receives that global permission even without 2FA configured, while the same requirement is correctly applied to project-, component-, and workspace-scoped permissions. Such a user can act on the granted global permission, including reaching the site management interface at /manage/. This issue is fixed in version 2026.7.
Title Weblate: Team-enforced 2FA is bypassed for global permissions
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-08-27T14:51:14.305Z

Reserved: 2026-07-10T20:06:05.617Z

Link: CVE-2026-61790

cve-icon Vulnrichment

Updated: 2026-08-27T14:51:08.879Z

cve-icon NVD

Status : Deferred

Published: 2026-08-26T21:16:39.353

Modified: 2026-09-09T21:09:13.080

Link: CVE-2026-61790

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-01T14:23:42Z

Weaknesses