Junglewise Threat Intelligence

CVE-2026-34393: Weblate privilege escalation in user API endpoint

CVE-2026-34393 · Severity: high · CVSS 8.8 · Published 2026-04-16

Technologies: weblate (PyPI). Vendors: PyPI.

Executive brief

Weblate, a web-based translation management system, contains a vulnerability that allows users to escalate their privileges. By exploiting a flaw in the user profile editing interface, an attacker with a standard account could modify settings beyond their authorized scope. This could lead to unauthorized access to sensitive translation data or administrative control over the platform.

Technical details

A privilege escalation vulnerability exists in Weblate's user patching API endpoint (CWE-269). The root cause is a failure to properly limit the scope of edits when a user profile is updated via the API. An authenticated attacker with low privileges can exploit this over the network to modify user attributes they should not have access to, potentially gaining administrative rights. The vulnerability is fixed in version 5.17.

Affected products

  • WeblateOrg Weblate < 5.17

Timeline

  • 2026-04-15: disclosed
  • 2026-04-15: patched
  • 2026-04-16: advisory

References

Related threats