Executive brief
Weblate, a web-based translation management system, contains a vulnerability that allows users to escalate their privileges. By exploiting a flaw in the user profile editing interface, an attacker with a standard account could modify settings beyond their authorized scope. This could lead to unauthorized access to sensitive translation data or administrative control over the platform.
Technical details
A privilege escalation vulnerability exists in Weblate's user patching API endpoint (CWE-269). The root cause is a failure to properly limit the scope of edits when a user profile is updated via the API. An authenticated attacker with low privileges can exploit this over the network to modify user attributes they should not have access to, potentially gaining administrative rights. The vulnerability is fixed in version 5.17.
Affected products
- WeblateOrg Weblate < 5.17
Timeline
- 2026-04-15: disclosed
- 2026-04-15: patched
- 2026-04-16: advisory