PT-2026-33114 · Weblate · Weblate

Published

2026-04-15

·

Updated

2026-04-16

·

CVE-2026-33214

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Weblate versions prior to 5.17
Description The translation memory API exposed unintended endpoints that failed to enforce proper access control.
Recommendations Update to version 5.17. As a temporary workaround, block access to the endpoint '/api/memory/' in the HTTP server to remove access to this feature.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-33214
GHSA-MPF5-3VPH-Q75R
PYSEC-2026-152

Affected Products

Weblate