CVE-2026-55227Medium· 4.3▾ SunlitPrivate Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 28.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
0.2%
Last analysed / modified upstream
0.2% → 0.2%
The several endpoints could leak object existence information to users who had no access to it by HTTP status code 403 instead of 404.
Thanks to Yaohui Wang for reporting this via GitHub.
weblate < 2026.7Upgrade to a patched release:
weblate 2026.7Connected by shared product, vendor, weakness, or advisory.
CVE-2026-55228High· 8.1Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
CVE-2026-34244Medium· 5.0Weblate: SSRF via Project-Level Machinery Configuration
CVE-2026-27457Medium· 4.3Weblate: Missing access control for the AddonViewSet API exposes all addon configurations
CVE-2026-33212Low· 3.1Weblate: Improper access control for pending tasks in API
CVE-2026-34242High· 7.7Weblate: Arbitrary File Read via Symlink
CVE-2026-44263Medium· 4.3Weblate Vulnerable to Private Translation Enumeration via Screenshot API