PT-2026-38400 · Weblate · Weblate

Luay89

·

Published

2026-05-07

·

Updated

2026-06-01

·

CVE-2026-44263

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Weblate versions prior to 5.17.1
Description The screenshots, tasks, and component link API endpoints allow for the enumeration of translations within a project that the user should not be able to access.
Recommendations Update to version 5.17.1.

Fix

Side Channel Attack

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44263
GHSA-GCG5-86JR-F7JG
OPENSUSE-SU-2026:10929-1

Affected Products

Weblate