PT-2026-2289 · Weblate+2 · Wlc+2

Zee99Y

·

Published

2026-01-12

·

Updated

2026-01-27

·

CVE-2026-22251

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions wlc versions prior to 1.17.0
Description wlc, a Weblate command-line client utilizing Weblate’s REST API, permitted the use of unscoped API keys in its settings before version 1.17.0. Although discouraged, the functionality was not removed, potentially leading to API key leakage to various servers.
Recommendations Update to version 1.17.0 or later.

Exploit

Fix

Information Disclosure

Insecure Storage of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2026-22251
GHSA-9RP8-H4G8-8766
USN-7981-1

Affected Products

Linuxmint
Ubuntu
Wlc