Impact
An authenticated user who has access to a project can call the nested API endpoint to retrieve the change history of components that are restricted from that user's view. The endpoint does not enforce the component‑level access checks that apply to direct component views, allowing enumeration of changes for hidden components. The data returned includes the component identity, translation and unit links, and sensitive change payload fields such as source or translated string content in the target, old, and details values. The exposure therefore results in a confidentiality breach of restricted translation information.
Affected Systems
The vulnerability affects Weblate versions prior to 2026.7. Specifically, any instance of the Weblate platform maintained by WeblateOrg in which projects contain restricted components may be impacted.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity; the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires authentication to a project and an awareness of the nested API endpoint, but does not require any elevated privileges beyond project access. The primary attack vector is an authenticated internal API call. Given these conditions, the likelihood of exploitation is relatively low, but the impact on confidentiality warrants prompt remediation.
OpenCVE Enrichment