Executive brief
Weblate is a web-based translation and localization tool. A security flaw in its task management interface could allow an authenticated user to view logs of ongoing background operations that they should not have permission to see. While this could expose sensitive operational details, an attacker would need to guess a complex unique identifier for the specific task, making successful exploitation difficult under standard configurations.
Technical details
An improper access control vulnerability (CWE-284) exists in the Weblate API for tasks. The affected component fails to verify if the requesting user has the appropriate scope or permissions to access logs of in-progress (pending) operations. An attacker with network access and low-level authenticated privileges could potentially view these logs. However, exploitation is hindered by the requirement to guess a random UUID associated with the task, which is further mitigated by default API rate limits. The issue is resolved in version 5.17.
Affected products
- WeblateOrg weblate < 5.17
Timeline
- 2026-04-15: patched: Version 5.17 released
- 2026-04-16: advisory