---
id: CVE-2026-27457
aliases:
  - GHSA-wppc-7cq7-cgfv
  - PYSEC-2026-2310
title: >-
  Weblate: Missing access control for the AddonViewSet API exposes all addon
  configurations
summary: >-
  Weblate: Missing access control for the AddonViewSet API exposes all addon
  configurations
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'
vendor: weblate
product: weblate
ecosystem: pip
affected:
  - weblate < 5.16.1
patched:
  - weblate 5.16.1
published: '2026-02-26'
updated: '2026-07-13'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-wppc-7cq7-cgfv'
references:
  - url: >-
      https://github.com/WeblateOrg/weblate/security/advisories/GHSA-wppc-7cq7-cgfv
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-27457'
  - url: 'https://github.com/WeblateOrg/weblate/pull/18107'
  - url: 'https://github.com/WeblateOrg/weblate/pull/18164'
  - url: >-
      https://github.com/WeblateOrg/weblate/commit/3f58f9a4152bc0cbdd6eff5954f9c7bc4d9f0af9
  - url: >-
      https://github.com/WeblateOrg/weblate/commit/7802c9b121eb407c48d4adddd4f2458fb3efef0f
  - url: 'https://github.com/WeblateOrg/weblate'
  - url: 'https://github.com/WeblateOrg/weblate/releases/tag/weblate-5.16.1'
tags:
  - osv
  - pip
epss: 0.00421
epssPercentile: 0.33793
ingestedAt: '2026-07-13T18:58:04.666Z'
---

## Overview

### Impact

Users were able to obtain add-on configuration via API.

### Patches

* https://github.com/WeblateOrg/weblate/pull/18107
* https://github.com/WeblateOrg/weblate/pull/18164


### References

Weblate thanks @lighthousekeeper1212 for responsible disclosure.

## Affected packages

- `weblate < 5.16.1`

## Remediation

Upgrade to a patched release:

- `weblate 5.16.1`
