Junglewise Threat Intelligence

CVE-2026-44263: Weblate translation enumeration via API information disclosure

CVE-2026-44263 · Severity: medium · CVSS 4.3 · Published 2026-05-07

Technologies: WeblateOrg Weblate. Vendors: PyPI.

Executive brief

Weblate, a web-based translation and localization platform, contained a security flaw in its programming interface (API). An authenticated user could exploit this to determine the existence of translation projects and components they were not authorized to see. This could lead to the exposure of private project names or internal organizational structures.

Technical details

An information disclosure vulnerability exists in Weblate's REST API due to insufficient access-filtered querysets in several endpoints, including screenshots, tasks, and component links. Specifically, the application failed to properly validate if a requesting user had permissions for a specific translation or component before returning a response that confirmed its existence (CWE-203). An authenticated attacker could use these API parameters to enumerate the names and existence of private projects or translations they cannot otherwise access. The fix, introduced in version 5.17.1, implements 'filter_access(user)' checks and ensures that lookups for categories and components are strictly scoped to the projects the user is authorized to view.

Affected products

  • WeblateOrg Weblate < 5.17.1

Timeline

  • 2026-04-27: patched: Fix committed to repository
  • 2026-04-30: advisory: Release 5.17.1 published
  • 2026-05-07: disclosed: CVE published

References

Related threats