CVE-2026-33212Low· 3.1▾ SunlitWeblate: Improper access control for pending tasks in API
▾ Sunlit zone — Low / medium · no exploitation signal
impact 17.1 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 13.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.2%
The API for tasks didn't verify user access for pending tasks. This could expose logs of in-progress operations to users who don't have access to given scope.
The attacker needs to guess the random UUID of the task, so exploiting this is unlikely with the default API rate limits.
This issue was identified by Michal Čihař.
weblate < 5.17Upgrade to a patched release:
weblate 5.17Connected by shared product, vendor, weakness, or advisory.
CVE-2026-55227Medium· 4.3Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups
CVE-2026-55228High· 8.1Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
CVE-2026-34244Medium· 5.0Weblate: SSRF via Project-Level Machinery Configuration
CVE-2026-27457Medium· 4.3Weblate: Missing access control for the AddonViewSet API exposes all addon configurations
CVE-2026-34242High· 7.7Weblate: Arbitrary File Read via Symlink
CVE-2026-44263Medium· 4.3Weblate Vulnerable to Private Translation Enumeration via Screenshot API