Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-55228— Weblate:: WebIDOR in GroupViewSet allows authenticated project manager to gain unauthorized read access to any private project

Quick assessment

Affected
WeblateOrg weblate
Exploitation
Public or AI PoC available; prioritize validation
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Weblate 是一个基于 Web 的持续本地化平台,用于管理软件翻译。在 2026.7 之前的版本中,REST API 未正确执行项目级和工作区级团队的权限范围限制,允许用户通过 API 提交无效的团队成员配置。通过将项目分配给未经验证的团队,用户可以获得其本不应具备查看或管理权限的项目的访问权。此问题可能导致私有项目被泄露,并允许用户在超出其预期权限范围的情况下执行翻译、代码仓库及项目管理等操作。该问题已在 2026.7 版本中修复。

CVSS 8.1 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-55228

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Weblate:: WebIDOR in GroupViewSet allows authenticated project manager to gain unauthorized read access to any private project
Source: CVE Program / CVE List V5
Vulnerability Description
Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, the REST API did not properly enforce the scope of project- and workspace-scoped teams, allowing a user to submit invalid team configurations through the API. By assigning projects to a team via these unvalidated requests, a user could grant access to projects they were not authorized to see or manage. This could expose private projects and permit translation, repository, and project-management operations outside the user's intended permission scope. This issue is fixed in version 2026.7.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
通过用户控制密钥绕过授权机制
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
WeblateOrg weblate < 2026.7 -

II. Public POCs for CVE-2026-55228

# POC Description Source Link Shenlong Link
AI-Generated POC Premium
Qwen3.6-35B-A3B · 7550 chars
Pro+ exclusive includes:
Vulnerability reproduction recording (real sandbox build + trigger, exclusive)
In-depth vulnerability mechanism
Trigger conditions & impact
Full executable POC code
Exploit chain & mitigation
POC zip download
100+ AI POC generations per month

III. Intelligence Information for CVE-2026-55228

登录查看更多情报信息。

Same Patch Batch · WeblateOrg · 2026-08-26 · 9 CVEs total

CVE-2026-61792 7.7 HIGH Weblate path traversal allows a project administrator to read arbitrary files via App stor
CVE-2026-62326 6.5 MEDIUM Weblate Has Uncontrolled Resource Consumption via
CVE-2026-77507 5.3 MEDIUM Weblate: Object-scoped RSS feeds disclose private change history to unauthorized users
CVE-2026-61790 4.4 MEDIUM Weblate: Team-enforced 2FA is bypassed for global permissions
CVE-2026-62249 4.3 MEDIUM Weblate: Restricted-component change history leaked to non-member project users through th
CVE-2026-55227 4.3 MEDIUM Observable object existence disclosure in private Weblate projects via globally scoped obj
CVE-2026-77508 3.5 LOW Weblate: Unverified REST API email changes
CVE-2026-77573 3.5 LOW Weblate: DNS rebinding in VCS operations allows server-side request forgery

IV. Related Vulnerabilities

V. Comments for CVE-2026-55228

No comments yet


Leave a comment