PT-2026-33114 · Weblate · Weblate

CVE-2026-33214

·

Published

2026-04-15

·

Updated

2026-04-16

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Weblate versions prior to 5.17
Description The translation memory API exposed unintended endpoints that failed to enforce proper access control.
Recommendations Update to version 5.17. As a temporary workaround, block access to the endpoint '/api/memory/' in the HTTP server to remove access to this feature.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-33214
GHSA-MPF5-3VPH-Q75R
PYSEC-2026-152

Affected Products

Weblate