Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-61790— Weblate: Team-enforced 2FA is bypassed for global permissions

Quick assessment

Affected
WeblateOrg weblate
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Weblate 是一个基于 Web 的持续本地化平台,用于管理软件翻译。在 2026.7 之前的版本中,团队可以要求成员在获得该团队的权限之前必须先配置双因素认证(2FA),但这一要求并未应用于站点范围的全局权限。因此,即使某个用户所属的团队强制启用 2FA 并授予了全局权限,该用户在未配置 2FA 的情况下仍能获得并使用该全局权限;而同一要求在项目、组件和工作区范围内的权限上是正确执行的。该用户能够行使所授予的全局权限,包括访问位于 的站点管理界面。此问题已在 2026.7 版本中修复。

CVSS 4.4 · Medium

Possible ATT&CK Techniques 1 AI

T1134.002 · Create Process with Token
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-61790

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Weblate: Team-enforced 2FA is bypassed for global permissions
Source: CVE Program / CVE List V5
Vulnerability Description
Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, a team can require its members to configure two-factor authentication before receiving the team's permissions, but this requirement is not enforced for site-wide global permissions. As a result, a user who belongs to a team that enforces 2FA and grants a global permission still receives that global permission even without 2FA configured, while the same requirement is correctly applied to project-, component-, and workspace-scoped permissions. Such a user can act on the granted global permission, including reaching the site management interface at /manage/. This issue is fixed in version 2026.7.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
访问控制不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
WeblateOrg weblate < 2026.7 -

II. Public POCs for CVE-2026-61790

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-61790

登录查看更多情报信息。

Patches & Fixes for CVE-2026-61790 (1)

Vendor Advisories for CVE-2026-61790 (1)

Same Patch Batch · WeblateOrg · 2026-08-26 · 9 CVEs total

CVE-2026-55228 8.1 HIGH Weblate:: WebIDOR in GroupViewSet allows authenticated project manager to gain unauthorize
CVE-2026-61792 7.7 HIGH Weblate path traversal allows a project administrator to read arbitrary files via App stor
CVE-2026-62326 6.5 MEDIUM Weblate Has Uncontrolled Resource Consumption via
CVE-2026-77507 5.3 MEDIUM Weblate: Object-scoped RSS feeds disclose private change history to unauthorized users
CVE-2026-62249 4.3 MEDIUM Weblate: Restricted-component change history leaked to non-member project users through th
CVE-2026-55227 4.3 MEDIUM Observable object existence disclosure in private Weblate projects via globally scoped obj
CVE-2026-77508 3.5 LOW Weblate: Unverified REST API email changes
CVE-2026-77573 3.5 LOW Weblate: DNS rebinding in VCS operations allows server-side request forgery

IV. Related Vulnerabilities

V. Comments for CVE-2026-61790

No comments yet


Leave a comment