Impact
Weblate’s object‑scoped RSS feeds bypass the permission checks that normally protect private projects and restricted components. As a result, an unauthenticated user can retrieve the change‑history metadata for translations, including project and component identities, contributor usernames and full names, action types, timestamps, and translation or unit links. The vulnerability does not expose the translated string content itself. The exposed data can be used to map user interactions, discover project structure, and facilitate further social engineering or targeted attacks.
Affected Systems
All installations of Weblate prior to version 2026.8 are affected when object‑scoped RSS feeds are enabled. This includes any private projects or components that restrict visibility. Systems that allow anonymous access to the web interface can expose the RSS feed data without requiring any authentication, amplifying the exposure. Upgrading to Weblate 2026.8 or later resolves the issue by correctly enforcing permission checks on these feeds.
Risk and Exploitability
The vulnerability carries a CVSS score of 5.3, indicating moderate severity. EPSS data is unavailable, and the issue is not listed in CISA KEV, suggesting limited current exploitation evidence. Attackers only need to know or guess the RSS feed URL for a private project; no code execution or elevated privileges are required. The primary risk is the leakage of metadata that could aid in reconnaissance or facilitate additional attacks, especially on installations with exposed anonymous access.
OpenCVE Enrichment