Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-77507— Weblate: Object-scoped RSS feeds disclose private change history to unauthorized users

Quick assessment

Affected
WeblateOrg weblate
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Weblate 是一个基于 Web 的持续本地化平台,用于管理软件翻译。在 2026.8 之前的版本中,Weblate 的对象级 RSS 订阅源未应用其他功能所使用的权限检查,导致未授权用户能够读取私有项目或受限组件的变更历史元数据。在允许匿名访问的实例中,这些元数据甚至可以在完全无认证的情况下被获取。暴露的信息可能包括项目和组件标识、贡献者的用户名和全名、操作类型、时间戳以及翻译或单元链接,但订阅源中不包含已翻译的字符串内容。使用私有项目或受限组件的实例均受此问题影响。该问题已在 2026.8 版本中修复。

CVSS 5.3 · Medium

Possible ATT&CK Techniques 1 AI

T1213 · Data from Information Repositories
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-77507

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Weblate: Object-scoped RSS feeds disclose private change history to unauthorized users
Source: CVE Program / CVE List V5
Vulnerability Description
Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.8, Weblate's object-scoped RSS feeds do not apply the permission checks used elsewhere, allowing unauthorized users to read change-history metadata from private projects and restricted components. On installations that permit anonymous access, this metadata can be retrieved without any authentication. The exposed information can include project and component identities, contributor usernames and full names, action types, timestamps, and translation or unit links, though translated-string content is not included in the feed. Installations using private projects or restricted components are affected. This issue is fixed in version 2026.8.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
信息暴露
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
WeblateOrg weblate < 2026.8 -

II. Public POCs for CVE-2026-77507

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-77507

登录查看更多情报信息。

Same Patch Batch · WeblateOrg · 2026-08-26 · 9 CVEs total

CVE-2026-55228 8.1 HIGH Weblate:: WebIDOR in GroupViewSet allows authenticated project manager to gain unauthorize
CVE-2026-61792 7.7 HIGH Weblate path traversal allows a project administrator to read arbitrary files via App stor
CVE-2026-62326 6.5 MEDIUM Weblate Has Uncontrolled Resource Consumption via
CVE-2026-61790 4.4 MEDIUM Weblate: Team-enforced 2FA is bypassed for global permissions
CVE-2026-62249 4.3 MEDIUM Weblate: Restricted-component change history leaked to non-member project users through th
CVE-2026-55227 4.3 MEDIUM Observable object existence disclosure in private Weblate projects via globally scoped obj
CVE-2026-77508 3.5 LOW Weblate: Unverified REST API email changes
CVE-2026-77573 3.5 LOW Weblate: DNS rebinding in VCS operations allows server-side request forgery

IV. Related Vulnerabilities

V. Comments for CVE-2026-77507

No comments yet


Leave a comment