Junglewise Threat Intelligence

CVE-2026-41519: Weblate insufficient session expiration for API tokens on password change

CVE-2026-41519 · Severity: medium · CVSS 4.2 · Published 2026-05-07

Technologies: WeblateOrg Weblate. Vendors: PyPI.

Executive brief

Weblate is a web-based platform used by organizations to manage software translation and localization. A security issue was identified where changing a user's password failed to revoke existing API tokens. If an account is compromised, an attacker with a stolen API token could maintain access to the platform even after the legitimate user resets their password, potentially allowing unauthorized modifications to translation data.

Technical details

In Weblate versions prior to 5.17.1, the password change process correctly invalidates browser sessions using 'cycle_session_keys()', but fails to revoke DRF API tokens (prefixed with 'wlu_*') stored in the 'authtoken_token' table. This results in a session management vulnerability (CWE-613) where an attacker who has obtained a user's API token can maintain access to the Weblate API even after the user has updated their credentials. The vulnerability is exploitable by an authenticated attacker who has previously compromised a token. The issue is resolved in version 5.17.1 by ensuring API tokens are regenerated by default during a password reset.

Affected products

  • WeblateOrg Weblate < 5.17.1

Timeline

  • 2026-04-17: patched: Fix merged into main branch
  • 2026-04-30: advisory: Release of version 5.17.1
  • 2026-05-07: disclosed: CVE published

References

Related threats