CVE-2026-24126Medium· 6.6▾ TwilightPoC availableWeblate has an argument injection in management console
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 36.3 · likelihood 0.1 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Jul 13.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.4%
1 GitHub repo
0.4% → 0.5%
The SSH management console did not validate the passed input while adding the SSH host key, which could lead to an argument injection to ssh-add.
Properly limit access to the management console.
This issue was reported to us by alexb_616 via HackerOne.
weblate < 5.16.0Upgrade to a patched release:
weblate 5.16.0Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-55227Medium· 4.3Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups
CVE-2026-55228High· 8.1Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
CVE-2026-34244Medium· 5.0Weblate: SSRF via Project-Level Machinery Configuration
CVE-2026-27457Medium· 4.3Weblate: Missing access control for the AddonViewSet API exposes all addon configurations
CVE-2026-33212Low· 3.1Weblate: Improper access control for pending tasks in API
CVE-2026-34242High· 7.7Weblate: Arbitrary File Read via Symlink